Search/blizzard
Vendor

blizzard

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
warcraft 3 the frozen throne
Connections
61 relationships
Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware
Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like hotels and conference centers, according to new findings from Microsoft Threat Intelligence. Overview of the CaptiveCrunch attack flow (Source: Microsoft) Microsoft named the campaign CaptiveCrunch and identified two malware strains behind it, CornFlake and ChocoShell. Building on earlier research from security firm ReliaQuest, published July 23, Microsoft ties this activity to Storm-2945, a sub-cluster of Midnight Blizzard. Microsoft says the broader operation, which shows signs of AI assistance, dates back to February 2026, with the traffic manipulation piece observed since early May. “Although our investigation into the initial compromise vector for the captive portal networks is ongoing, we have observed notable commonalities in the equipment and management systems used across multiple affected networks. These similarities suggest that the activity might not be limited to isolated compromises of individual venues and could reflect access to shared services within portions of the captive portal ecosystem,” Microsoft wrote. By manipulating DNS and HTTP traffic on compromised captive portal networks, the attackers redirected victims down three paths. Two led to credential theft: phishing pages impersonating Microsoft 365 sign-in portals, and device code phishing pages abusing Microsoft Entra ID authentication flows. The third displayed fake browser or operating system update pages that used the ClickFix social engineering method to persuade victims to download and run malware. Microsoft also found ClickFix pages configured to push an APK file, suggesting the threat actor might be targeting Android devices too. CornFlake and ChocoShell Researchers describe CornFlake as a Windows RAT written in Go with a wide range of capabilities that include: Keylogging Clipboard monitoring Screenshot capture Audio surveillance Video surveillance Browser credential theft File exfiltration USB drive monitoring Security posture sweep Remote shell access “On initial execution, CornFlake operates in dropper mode: it displays a convincing fake progress window designed to occupy the victim’s attention while the binary copies itself to %APPDATA%\svchost32\svchost32.exe and establishes persistence,” they added. The second identified malware, ChocoShell, is an in-memory PowerShell credential stealer targeting browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. “Where CornFlake provides the operator with a persistent, long-running foothold on the device, ChocoShell is designed to extract the most operationally valuable credentials, giving the operator access to victim cloud environments,” Microsoft noted. Researchers also discovered a web-based C2 panel, FruitStone, that Storm-2945 operators use to run the CaptiveCrunch infrastructure. Built as a single-page HTML and JavaScript application with no authentication on any of its functions, it gives operators a dashboard for managing compromised endpoints, building and deploying new payloads, and reviewing collected data such as screenshots, keystrokes, and browser credentials. Recommendations Microsoft recommends treating hotel and conference Wi-Fi as untrusted, using private cellular or managed connections where practical, and avoiding software updates or tools offered through captive portals. Organizations are advised to review what information employees provide to hospitality providers when connecting to guest networks. “Organizations should assume that public and hospitality network infrastructure might not be trustworthy and should adopt controls that limit exposure to traffic manipulation, credential theft, and device code phishing,” Microsoft concluded.
helpnetsecurity.comAug 4, 2026extracted
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. The activity was previously disclosed in a report from cybersecurity company ReliaQuest, which detailed how the attacker changed DNS settings on Wi-Fi devices to steal Microsoft 365 accounts. Besides attributing the campaign to Russian hackers tracked as Storm-2945 - a sub-cluster of Midnight Blizzard, Microsoft identified two malware families called CornFlake and ChocoShell with capabilities for persistent access, credential theft, surveillance, and data exfiltration. Microsoft named the campaign CaptiveCrunch and believes it has been active since at least early May, although the threat actor has been running device and OAuth code phishing operations since February. Attack chain The attackers manipulate DNS and HTTP traffic on networks served by captive portal equipment, allowing them to intercept user connections to hotel and conference center Wi-Fi networks. Like ReliaQuest, Microsoft was unable to determine the exact initial compromise, although it noted signs of breaches in shared infrastructure rather than isolated devices. After modifying DNS settings, the attacker can redirect victims to phishing pages that impersonate Microsoft 365 login portals, or to device code phishing pages that abuse Microsoft Entra ID authentication flows. Microsoft observed this activity since July. A third option not previously disclosed involves using fake browser and operating system update pages that deliver malware to Windows via ClickFix prompts for user verification. Microsoft also found evidence in some ClickFix landings indicating that the threat actor is also targeting Android devices to deliver an APK file. CornFlake and ChocoShell malware Microsoft analyzed the two new Windows malware families and found that CornFlake is a Go-based remote access trojan (RAT) that offers the following capabilities: Remote shell access Keylogging Clipboard monitoring Screenshot capturing Microphone and webcam surveillance Browser credential and cookie theft Microsoft 365 session token theft File exfiltration USB monitoring System reconnaissance When executed, CornFlake shows a fake progress window to distract the user while the binary copies to %AppData% for persistence. According to the researchers, the bogus window can be configured to appear as a Windows update screen, a Defender virus scan, a disk optimization utility, a network diagnostics tool, a browser update prompt, or a document viewer installer. CornFlake disguises itself as “Cloud Sync Service” to appear as a legitimate Windows component, and uses multiple persistence mechanisms on the host, including Windows service registrations, registry run keys, named tasks, and a watchdog routine designed to restore any of the available persistence mechanisms. The second payload, ChocoShell, is an in-memory PowerShell credential stealer that targets browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. Based on the extensive comments in the code, Microsoft assesses that AI tools were likely used to develop the two pieces of malware. The researchers also discovered an unprotected web-based management panel named FruitStone that the threat actor used to handle infected systems, browse victim files, execute PowerShell commands, and capture screenshots and keystrokes. Microsoft recommends treating hotel and conference Wi-Fi as untrusted, using private cellular or managed connections whenever possible, and avoiding software updates or tools offered through captive portals. It is also recommended to adopt phishing-resistant authentication with MFA and passkeys, disable Microsoft Entra device code authentication when not needed, and avoid using corporate credentials to register for guest Wi-Fi networks. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 4, 2026extracted
Midnight Blizzard Targets Travelers via Captive Portals
Captive portals on hotel and conference Wi-Fi networks have been hijacked to route guests through attacker infrastructure, serving fake browser and operating system updates that install Russian espionage malware. According to research published by Microsoft Threat Intelligence on July 31, the campaign, which it named CaptiveCrunch, has run since early May and is attributed to Storm-2945, a sub-cluster of Midnight Blizzard. The US and UK government have previously attributed Midnight Blizzard (also known as APT29, the Dukes, or Cozy Bear) to Russia's Foreign Intelligence Service, the SVR. Microsoft is still investigating how the portals were compromised but noted commonalities in the equipment and management systems across affected networks, which it said could reflect access to shared services within the captive portal ecosystem rather than isolated venue compromises. Fake Updates Triggered by Connectivity Checks Rather than waiting for a user to visit a website, the threat actor answered the automated connectivity checks that browsers and operating systems issue on joining a new network. Those checks returned pages offering browser or system updates. The landings used ClickFix techniques, presenting fake verification failures with paste-and-run instructions. Microsoft said some also served an APK, indicating possible Android targeting. From July 16, some pages redirected users into device code authentication flows, instructing them to enter an attacker-supplied code on a genuine Microsoft sign-in page. Microsoft said the technique was not new but embedding it in a captive portal made the request more likely to seem legitimate. ReliaQuest, which reported part of the activity on July 23, found it at hotels, conference centers and other shared venues, targeting corporate travelers' accounts. Three Tools, One Cover Story The primary implant is CornFlake, a Go remote access trojan (RAT) that displays a fake progress window while installing itself, then registers as a Windows service with the display name Cloud Sync Service. It carries keylogging, screenshots, microphone and webcam surveillance, browser credential theft and a remote shell, plus a watchdog routine that restores any persistence mechanism defenders remove. A PowerShell infostealer called ChocoShell runs entirely in memory, disabling the Antimalware Scan Interface (AMSI) before harvesting browser cookies, saved passwords, Microsoft 365 single sign-on tokens and Wi-Fi credentials. Its developer comments named specific Microsoft detection signatures and explained each evasion choice, which Microsoft said suggested AI-assisted code generation. The company said the actor used AI across a significant portion of the operation and thanked Anthropic and OpenAI for their support during the investigation. Operators run the campaign from FruitStone, a web panel branded as a fictitious enterprise cloud product, matching the implant's cover story. Microsoft's recommendations include treating hotel, conference and airport wireless as untrustworthy, preferring cellular or eSIM connectivity and never installing software offered through a captive portal. It also advised blocking device code flow where it is not required and deploying passkeys. Captive portals on hotel and conference Wi-Fi networks have been hijacked to route guests through attacker infrastructure, serving fake browser and operating system updates that install Russian espionage malware. According to research published by Microsoft Threat Intelligence on July 31, the campaign, which it named CaptiveCrunch, has run since early May and is attributed to Storm-2945, a sub-cluster of Midnight Blizzard. The US and UK government have previously attributed Midnight Blizzard (also known as APT29, the Dukes, or Cozy Bear) to Russia's Foreign Intelligence Service, the SVR. Microsoft is still investigating how the portals were compromised but noted commonalities in the equipment and management systems across affected networks, which it said could reflect access to shared services within the captive portal ecosystem rather than isolated venue compromises. Fake Updates Triggered by Connectivity Checks Rather than waiting for a user to visit a website, the threat actor answered the automated connectivity checks that browsers and operating systems issue on joining a new network. Those checks returned pages offering browser or system updates. The landings used ClickFix techniques, presenting fake verification failures with paste-and-run instructions. Microsoft said some also served an APK, indicating possible Android targeting. From July 16, some pages redirected users into device code authentication flows, instructing them to enter an attacker-supplied code on a genuine Microsoft sign-in page. Microsoft said the technique was not new but embedding it in a captive portal made the request more likely to seem legitimate. ReliaQuest, which reported part of the activity on July 23, found it at hotels, conference centers and other shared venues, targeting corporate travelers' accounts. Three Tools, One Cover Story The primary implant is CornFlake, a Go remote access trojan (RAT) that displays a fake progress window while installing itself, then registers as a Windows service with the display name Cloud Sync Service. It carries keylogging, screenshots, microphone and webcam surveillance, browser credential theft and a remote shell, plus a watchdog routine that restores any persistence mechanism defenders remove. A PowerShell infostealer called ChocoShell runs entirely in memory, disabling the Antimalware Scan Interface (AMSI) before harvesting browser cookies, saved passwords, Microsoft 365 single sign-on tokens and Wi-Fi credentials. Its developer comments named specific Microsoft detection signatures and explained each evasion choice, which Microsoft said suggested AI-assisted code generation. The company said the actor used AI across a significant portion of the operation and thanked Anthropic and OpenAI for their support during the investigation. Operators run the campaign from FruitStone, a web panel branded as a fictitious enterprise cloud product, matching the implant's cover story. Microsoft's recommendations include treating hotel, conference and airport wireless as untrustworthy, preferring cellular or eSIM connectivity and never installing software offered through a captive portal. It also advised blocking device code flow where it is not required and deploying passkeys.
infosecurity-magazine.comAug 3, 2026extracted
Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
A Russian state-sponsored APT is behind a recent credential theft campaign mounted via hacked public Wi-Fi gateway appliances at organizations running captive portal networks, Microsoft reports. The campaign was flagged roughly a week ago by ReliaQuest, which noticed that hackers had modified the DNS configurations of compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure. The attackers were using the adversary-in-the-middle (AitM) technique to intercept the Microsoft 365 credentials of traveling employees within the financial services, professional services, legal, healthcare, energy, and retail sectors. ReliaQuest pointed out that the campaign shared similarities with FrostArmada, an espionage operation mounted by Russia-linked APT28 (also known as Forest Blizzard and Fancy Bear), but did not make a clear attribution. Now Microsoft says that Storm-2945, a subgroup of Midnight Blizzard (also tracked as APT29, Cozy Bear, the Dukes, and Yttrium), a threat actor believed to be sponsored by the Russian Foreign Intelligence Service (SVR), is behind the fresh campaign, dubbed CaptiveCrunch. Midnight Blizzard is known for targeting government and diplomatic entities, non-governmental organizations (NGOs), and IT services providers in the US and Europe for intelligence gathering in support of Russian foreign policy interests. “Midnight Blizzard operations often involve compromise of valid accounts and, in some highly targeted cases, advanced techniques to compromise authentication mechanisms within an organization to expand access and evade detection,” Microsoft notes. Storm-2945, the tech giant says, started manipulating DNS and HTTP traffic from captive portal networks, such as those at hotels, conference centers, and other shared venues, in May, likely through access to shared services within the captive portal ecosystem. As part of CaptiveCrunch, the attackers have been serving Golang-based Windows remote access trojans (RATs) in the form of browser updates. The malware enabled reconnaissance, credential and session token theft, file and keystroke collection, audio and video surveillance, and remote shell access. The threat actor has been using various ClickFix techniques to convince users to download malware and appears to have been targeting Android users with similar methods to entice them into fetching and installing an APK file. “To date, Microsoft has identified widespread compromise of Wi-Fi networks at hospitality-related organizations and other networks serviced by captive portal equipment in several countries,” the company notes. Storm-2945 targeted Windows users with the CornFlake RAT and infostealer implant and the ChocoShell PowerShell-based infostealer, and managed its infrastructure and agents via the FruitStone web-based command-and-control (C&C) panel. Over the past two weeks, Microsoft says, some CaptiveCrunch landing pages have been directing victims to device code authentication flow experiences, instructing them to enter device codes into Microsoft sign-in pages to authenticate the threat actor’s session. “This activity is consistent with previously reported device code phishing operations conducted by Midnight Blizzard since August 2024. The observed technique does not appear fundamentally novel; however, integrating device code phishing into captive portal and traffic manipulation operations might increase the likelihood that users perceive the authentication request as legitimate,” Microsoft notes. Related: US Charges Russian Individuals and Firms for Running Cybercrime Services Related: US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers
securityweek.comAug 3, 2026extracted
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as APT29 and Cozy Bear. The U.S. and U.K. governments attribute the broader actor to Russia's Foreign Intelligence Service (SVR). On the compromised networks ReliaQuest investigated, the captive portal gateway also served as the DNS resolver assigned to connected devices. Administrative control of that gateway let the attackers forge Domain Name System (DNS) answers and redirect the resulting traffic. They could then redirect a laptop's automatic connectivity check to a fake browser or operating system update. Some pages use ClickFix instructions that tell victims to open a terminal or another Windows utility and run an attacker-supplied command. The gateway controls where the user is sent, but it does not silently infect the endpoint. The victim still has to download or execute the payload. Microsoft has observed the traffic manipulation since early May across hospitality networks in several countries, but it has not named a hotel, venue, or captive portal vendor. ReliaQuest recommends an always-on, full-tunnel virtual private network (VPN), which sends DNS queries through corporate resolvers before the venue's gateway can answer them. Researchers advise travelers to use private connections and reject software updates, certificates, browser updates, troubleshooting tools, or security utilities offered through captive portals. Since July 16, some CaptiveCrunch landing pages have redirected guests into Microsoft's device code authentication flow. Entering the attacker-supplied code on Microsoft's legitimate sign-in page can grant the attacker-controlled session multi-factor authentication (MFA)-satisfied access. Microsoft recommends blocking the flow through Conditional Access wherever it is not needed. CornFlake, a Go-based implant, copies itself to %APPDATA%\svchost32\svchost32.exe and registers the svchost32 service under the display name Cloud Sync Service. A fake progress window holds the victim's attention while this happens. Microsoft's analysis says the implant can take idle-triggered screenshots, record clipboard contents with the active window title, steal browser cookies and saved passwords, including cookies protected by Chrome App-Bound Encryption, scan removable media, and open a remote shell. It also uses a Registry Run key and a scheduled task, while a watchdog restores any persistence mechanism defenders remove. Researchers also identified ChocoShell, an in-memory PowerShell stealer. It collects Microsoft 365 and Azure Active Directory access and refresh tokens, plus Web Account Manager (WAM) tokens, from .tbres files in the Token Broker cache. The stolen tokens can enable session replay without a browser cookie. The reports document active redirection and malware delivery, but do not quantify their reach or conversion. Without counts of successful executions, device-code approvals, or stolen accounts, the public record does not show how often a redirect became a compromise. Microsoft found common equipment and management systems across the affected networks, which it says could reflect access to shared services within portions of the captive portal ecosystem. If so, the compromises may not have been isolated to individual venues. Microsoft has not named any affected provider. ReliaQuest documented the same Microsoft-impersonating domains and overlapping infrastructure eight days earlier. It said the tradecraft resembled APT28, the GRU unit also called Fancy Bear and Forest Blizzard, but stopped short of attribution because the assessment rests on TTP overlap rather than direct technical linkage. Microsoft acknowledges the similarity to the Forest Blizzard router hijacking it disclosed in April while attributing CaptiveCrunch to Storm-2945. The U.K. National Cyber Security Centre and its international partners assess that APT29 is almost certainly part of Russia's Foreign Intelligence Service. That government attribution covers the broader APT29 group. The CaptiveCrunch-to-Storm-2945 link remains Microsoft's assessment. No separate public technical report has independently corroborated it. The initial compromise vector remains under investigation. ReliaQuest assesses with low-to-medium confidence that a combination of exposed management interfaces and weak or reused administrator credentials may have provided access, but said visibility constraints prevented confirmation.
thehackernews.comAug 1, 2026extracted
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. Email security company Proofpoint spotted the activity a week ago targeting various organizations, including government entities in the U.S. and Europe, and companies in the telecommunications, financial, hospitality, and aerospace sectors. Laundry Bear exploited CVE-2026-42897, a cross-site scripting (XSS) vulnerability that allows executing arbitrary JavaScript in the browser context when users open a specially crafted email in the Outlook Web Access (OWA) app. Previously, the same hackers leveraged another XSS vulnerability (CVE-2025-66376) as a zero-day in Zimbra email servers to deliver malware ZimReaper that steals email communication, two-factor authentication (2FA) codes, application passcodes, and passwords. Proofpoint researchers refer to this sort of XSS activity on webmail platforms as a “half-click exploit” because users only need to open the malicious email to trigger the exploited vulnerability. Improper HTML sanitization In a new report today, Proofpoint describes Laundry Bear’s new half-click exploit campaign as a significant “improvement in the group’s tradecraft and capability.” Based on Microsoft’s advisory on May 14 for the CVE-2026-42897 flaw in OWA, the threat actor was already exploiting it as a zero-day. The security issue causes the server to improperly sanitize the HTML code in the message body, which could be leveraged to run JavaScript when opening the email. According to Proofpoint, Laundry Bear, which the company tracks as TA488, had created the attack infrastructure for the OWAReaper campaign in March, almost two months before Microsoft’s warning. In the latest observed activity, the threat actor used messages on topics of interest to the target, such as supply-chain analyses, research updates, and performance indicators for tourism and gas markets. “The subject lines and lures are banal, likely so the targeted user opens and skims the message, but dismisses the message as junk without reporting it, especially given that there are no suspicious URLs or attachments present.” Proofpoint explains that the attacker leverages the improper sanitization issue to include malicious code in the messages to add HTML and JavaScript in the malicious messages. Emails contained a JavaScript loader and Base64-encoded payload blobs embedded in social media icon URLs after the ‘#’ character. The exploit delivers a backdoor that researchers call OWAReaper and describe as “the most sophisticated backdoor delivered via half-click exploits” they saw. Analysis revealed a “suite of subtle persistence mechanisms” and revealed it to be an evolution of the ZimReaper malware observed in the attacks against Zimbra email servers. “OWAReaper is executed entirely in the Outlook Web Access (OWA) reading pane. Upon execution, it uses Outlook APIs to rewrite the email on the Exchange server and remove the exploit content. Simultaneously, it disables OWA pop-ups and right-click ability while it runs,” Proofpoint says. The malware collects the compromised account’s email address, username, and Outlook settings. It also tries to steal the access credentials by creating invisible elements in the Document Object Model (DOM) and waiting for the browser to automatically fill them in. Long-term persistence mechanism Proofpoint researchers discovered that TA488 (Laundry Bear, Void Blizzard) can maintain access to a target’s mailbox even if their system is restored from a clean image or credentials are rotated. The threat actor achieves this through OWAReaper, which checks for installed Outlook add-ins that have ReadWriteMailbox permissions and uses them to steal OAuth tokens through the GetClientAccessToken operation request. “It then calls UpdateFolder to grant itself Owner-level permissions to the 'Default’ user (a low-permission preset alias in all Microsoft Exchange tenants) on every mail folder,” the researchers explain. This allows attackers to access the mailbox from any authenticated account within the organization. Because mailbox permissions are configured on the server side, changing the compromised user's credentials or reinstalling the affected system does not revoke the attackers' access. OWAReaper implements a second persistence mechanism by enabling caching and injecting a malicious iframe in the HTML of messages stored in OWA's offline IndexedDB. “This iframe executes every time the victim opens a poisoned email from the cache,” the researchers say. Two of everything The malware supports two command-and-control (C2) mechanisms for receiving instructions from the attacker. One of them uses GitHub commit messages as the communication channel. Every 24 hours, the malware queries GitHub's Commit Search API for encrypted messages that match a specific format and include the target's email address. OWAReaper can also parse emails delivered to the target’s mailbox. It checks the IndexedDB for message bodies with the {target_email_address}{space}{Base64text} structure. Laundry Bear also used two methods to exfiltrate data, the main one using HTTPS with AES-CTR encrypted URI paths that would be proxied through certain image content delivery network (CDN) domains. If the primary method fails, the data is delivered directly to the attacker’s server, which is defined in the function that initializes outbound network sessions. There is also a DNS exfiltration fallback, where data is encrypted, then encoded in packets using the Base32 method. Proofpoint attributed the OWAReaper campaign to the TA488 threat actor based on behavioral overlaps with the ZimReaper activity and the use of half-click XSS exploits to target webmail viewers for espionage purposes. The researchers published a small set of indicators of compromise (IoCs) that includes the domains used and the HTML message body with the CVE-2026-42897 exploit and the OWAReaper payload. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 29, 2026extracted
Russian hackers exploit unpatched Zimbra servers to steal emails
Russian hackers exploit unpatched Zimbra servers to steal emails Russian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform. Laundry Bear (also known as Void Blizzard, CL-STA-1114, and TA488) has been running the campaign since July 2025, according to a joint advisory from the NSA, FBI, CISA, and cybersecurity agencies from the Netherlands, UK, Australia, Canada, and a dozen other countries. “Laundry Bear’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data,” according to the joint security alert. Victims span the defense industrial base, federal and local government, education, energy, law enforcement, media, non-government organizations, and technology. Laundry Bear was first identified in May 2025, after Dutch intelligence traced a breach at the Dutch National Police back to a group stealing session cookies to get into police employee accounts. Attackers weaponize Zimbra XSS vulnerability The attackers’ latest campaign targets CVE-2025-66376, a cross-site scripting (XSS) vulnerability in the Zimbra web-based email and collaboration suite that was patched in November 2025. The advisory notes the group kept using the exploit even after the fix came out, meaning unpatched servers stay exposed. The flaw allows JavaScript embedded in a specially crafted HTML email to execute when the message is viewed, enabling attackers to steal account data without requiring the victim to click a link or visit a phishing page. “Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, Laundry Bear’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service,” reads the advisory. CISA says Laundry Bear’s exploit is used to collect victims’ last 90 days of email, email addresses and passwords, the organization’s email directory (including the Global Address List), two-factor authentication tokens, and newly created application passcodes. “The collected data is almost certainly further exfiltrated to internal network resources for review and long-term retention,” the agencies added. Cloud servers and VPNs conceal attacker activity Stolen data lands on a backend the advisory calls Flowerbed, a set of Docker containers running on rented cloud servers. One container, “Catcher,” acts as both a DNS and HTTP server to receive the stolen data. Another handles Let’s Encrypt certificates so the traffic looks like ordinary encrypted web traffic. The group leans on Mullvad VPN when logging into these servers and swaps out its infrastructure every 7 to 60 days, which makes long-term tracking harder. “The simplistic Flowerbed codebase has indications that artificial intelligence (AI) played a role in its development,” the advisory notes. What organizations should do To mitigate the risk, organizations are recommended to update their Zimbra deployments to the latest available versions, review the published IOCs, and check for connections to the identified domains and IP addresses. They should also watch authentication activity for anomalies, revoke unauthorized application passcodes, particularly ones created under the “ZimbraWeb” name, and check accounts for unauthorized mailbox access. “While Application Passcodes have non-malicious purposes, in this case instances of these passcodes with the name “ZimbraWeb” are almost certainly malicious,” the advisory warns.
helpnetsecurity.comJul 24, 2026extracted
Russian hackers exploit Zimbra zero-click flaw for email theft
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. According to CISA, Laundry Bear has targeted and compromised users in organizations associated with the Defense Industrial Base (DIB), federal and local government, education, energy, law enforcement, media, non-governmental organizations, and technology. The attackers exploit the Zimbra CVE-2025-66376 flaw, a cross-site scripting (XSS) vulnerability affecting Zimbra Collaboration Suite's Classic UI. The flaw allows JavaScript embedded in specially crafted HTML emails to execute automatically when a victim views the message, enabling attackers to steal account data without requiring the user to click a link or visit a phishing site. According to CISA, Laundry Bear exploited the flaw as a zero-day before Zimbra patched it in November 2025 and continues to target organizations running unpatched servers. The vulnerability was later tagged by CISA as actively exploited in attacks. CISA says Laundry Bear's exploit is used to automatically collect and send the victim's last 90 days of emails, email address, password, Global Address List (GAL), and two-factor authentication (2FA) tokens. The attackers also create and send back a new Zimbra application passcode, which is used by legacy email clients like IMAP or ActiveSync that do not support the TOTP authentication flows. Using a passcode allows the attackers to retain access to the email account while bypassing MFA. According to CISA, the malware exfiltrates stolen information over both DNS and HTTPS to an actor-controlled server running the group's "Flowerbed" collection framework. Smaller data is encoded and transmitted in DNS A-record queries, while larger payloads, including mailbox data, are uploaded over HTTPS as compressed archives to the attacker-controlled servers. In addition to exploiting the Zimbra flaw, Laundry Bear also utilizes adversary-in-the-middle (AiTM) phishing kits designed to impersonate legitimate Zimbra login portals, stealing credentials and session cookies, allowing the attackers to gain access to targets' email accounts. CISA released IOCs that show the campaign used sites that impersonate Zimbra infrastructure, using domain names like 'mailnalysis.com', 'emailanalytics.com.ua', 'zimbrastat.com', 'zimbra-metadata.com', 'istc-cloud.com', and 'zmailanalytics.com'. The advisory recommends that organizations using Zimbra: Update to the latest version of the software to install all available security updates. Review the published indicators of compromise. Investigate systems for connections to the identified domains and IP addresses. Monitor for suspicious authentication activity. Revoke any unauthorized application passcodes, especially those with the 'ZimbraWeb'. Review accounts for unauthorized mailbox access. CISA also recommends implementing phishing-resistant multi-factor authentication where possible. Laundry Bear targeted governments, police, and Ukraine The Laundry Bear hacking group was first attributed to cyberespionage attacks in May 2025 by the Dutch intelligence agencies. The Dutch agencies publicly attributed the group to a 2024 compromise of the Dutch National Police that exposed the personal information of police personnel and led to the identification of a previously unknown Russian espionage group. Microsoft tracks the same group under the name Void Blizzard. Since at least 2024, the group has focused on intelligence collection against organizations aligned with Russian strategic interests, primarily targeting NATO member states and Ukraine. Microsoft has also documented successful compromises of organizations supporting Ukraine, including entities in the defense, transportation, and aviation sectors. Earlier this year, BleepingComputer reported on a separate Laundry Bear campaign targeting Ukraine's military using charity-themed phishing emails to deliver malware disguised as donation requests. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 23, 2026extracted
Hacker linked to Void Blizzard faces charges over cyberespionage campaign
Hacker linked to Void Blizzard faces charges over cyberespionage campaign A Russian national with suspected links to the Void Blizzard hacking group appeared in U.S. federal court this week on charges of supporting a Kremlin-linked cyberespionage campaign that targeted U.S. companies, according to media reports. Denis Obrezko, 36, made his initial appearance in federal court in Boston on Tuesday after being transferred to U.S. custody from Thailand, where he was arrested last November. Russian state media previously reported that Obrezko is a native of the southwestern Russian city of Stavropol and had worked for Russian technology companies developing high-tech systems for domestic industries. U.S. prosecutors allege that Obrezko helped the Russian state-linked threat actor Void Blizzard gain unauthorized access to computers by providing infrastructure used to support the group's cyber operations, Reuters reported on Thursday. The Justice Department, which is prosecuting the case, did not respond to a request for comment. Obrezko reportedly remains in custody as the case moves forward. Prosecutors allege that cryptocurrency transactions linked to him were used to purchase a virtual private server and internet domain that facilitated attacks against organizations in the United States and other countries. According to an FBI affidavit filed in the case, investigators have identified at least 11 U.S. companies that were compromised, although authorities believe the actual number of victims is significantly higher. Thai authorities arrested Obrezko in early November during a joint operation with the FBI on the resort island of Phuket after raiding his hotel room, where investigators seized laptops, mobile phones and cryptocurrency wallets. Russian diplomats later visited Obrezko in detention and sought his return to Russia, while Moscow separately placed him on an international wanted list earlier this year. Researchers have described Void Blizzard as a relatively new threat group operating in support of Russian government interests. The hackers have targeted government agencies, defense contractors, transportation companies, media organizations, healthcare providers and nongovernmental organizations across Europe and North America, typically using purchased or stolen credentials to infiltrate networks and steal emails and internal documents. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaJun 11, 2026extracted
Russian hackers turn Kazuar backdoor into modular P2P botnet
The Russian hacker group Secret Blizzard has developed its long-running Kazuar backdoor into a modular peer-to-peer (P2P) botnet designed for long-term persistence, stealth, and data collection. Secret Blizzard, whose activity overlaps that of Turla, Uroburos, and Venomous Bear, has been associated with the Russian intelligence service (FSB) and is known for targeting government and diplomatic organizations, defense-related entities, and critical systems across Europe, Asia, and Ukraine. The Kazuar malware has been documented since 2017, and researchers found that its code lineage goes as far back as 2005. Its activity has been linked to the Turla espionage group working for the FSB. In 2020, researchers exposed its deployment in attacks targeting European government organizations. Three years later, it was seen deployed in attacks against Ukraine. “Leading” Kazuar Microsoft researchers analyzed a recent variant of Kazuar and observed that the malware now operates using three distinct modules: kernel, bridge, and worker. The Kernel module is the central coordinator that manages tasks, controls other modules, elects a leader, and orchestrates communications and data flow across the botnet. The leader is essentially one infected system within a compromised environment or network segment, which communicates with the command-and-control (C2) server, receives tasks, and forwards them internally to the other infected systems. Non-leader systems enter “silent” mode and don’t communicate directly with the C2. This results in better stealth and reduced detection surface. “The Kernel leader is the one elected Kernel module that communicates with the Bridge module on behalf of the other Kernel modules, reducing visibility by avoiding large volumes of external traffic from multiple infected hosts,” explains Microsoft. The process for selecting the leader is internal and autonomous, using uptime, reboot, and interruption counts. The Bridge module acts as the external communications proxy that relays traffic between the elected Kernel leader and the remote C2 infrastructure using protocols like HTTP, WebSockets, or Exchange Web Services (EWS). Internal communications rely on IPC (inter-process communication), including Windows Messaging, Mailslots, and named pipes, blending well with normal operational noise. The messages are AES-encrypted and serialized with Google Protocol Buffers (Protobuf). The Worker module performs the actual espionage operations, such as: keylogging capturing screenshots harvesting data from the filesystem performing system and network reconnaissance collecting email/MAPI data (including Outlook downloads) monitoring windows stealing recent files The collected data is encrypted, staged locally, and later exfiltrated through the Bridge module. Microsoft underlines Kazuar's versatility, which now supports 150 configuration options allowing operators to enable/disable specific security bypasses, perform task scheduling, time the data theft and size of exfiltration chunks, perform process injection, manage tasks and command execution, and more. Regarding the security bypass options, Kazuar now offers Antimalware Scan Interface (AMSI) bypass, Event Tracing for Windows (ETW) bypass, and Windows Lockdown Policy (WLDP) bypass. Secret Blizzard typically seeks long-term persistence on target systems for intelligence collections. The actor exfiltrates documents and email content that has political importance. Microsoft recommends that companies focus their defense on behavioral detection rather than static signatures, as Kazuar’s modular and highly configurable nature makes the threat particularly evasive. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 16, 2026extracted
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
The Russian threat actor known as APT28 (aka Forest Blizzard and Pawn Storm) has been linked to a fresh spear-phishing campaign targeting Ukraine and its allies to deploy a previously undocumented malware suite codenamed PRISMEX. "PRISMEX combines advanced steganography, component object model (COM) hijacking, and legitimate cloud service abuse for command-and-control," Trend Micro researchers Feike Hacquebord and Hiroyuki Kakara said in a technical report. The campaign is believed to be active since at least September 2025. The activity has targeted various sectors in Ukraine, including central executive bodies, hydrometeorology, defense, and emergency services, as well as rail logistics (Poland), maritime and transportation (Romania, Slovenia, Turkey), and logistical support partners involved in ammunition initiatives (Slovakia, Czech Republic), and military and NATO partners. The campaign is notable for the rapid weaponization of newly disclosed flaws, such as CVE-2026-21509 and CVE-2026-21513, to breach targets of interest, with infrastructure preparation observed on January 12, 2026, exactly two weeks before the former was publicly disclosed. In late February 2025, Akamai also disclosed that APT28 may have weaponized CVE-2026-21513 as a zero-day based on a Microsoft Shortcut (LNK) exploit that was uploaded to VirusTotal on January 30, 2026, well before the Windows maker pushed out a fix as part of its Patch Tuesday update on February 10, 2026. This pattern of zero-day exploitation indicates that the threat actor had advanced knowledge of the vulnerabilities prior to them being revealed by Microsoft. An interesting overlap between campaigns exploiting the two vulnerabilities is the domain "wellnesscaremed[.]com." This commonality, combined with the timing of the two exploits, has raised the possibility that the threat actors are stringing together CVE-2026-21513 and CVE-2026-21509 into a sophisticated two-stage attack chain. "The first vulnerability (CVE-2026-21509) forces the victim's system to retrieve a malicious .LNK file, which then exploits the second vulnerability (CVE-2026-21513) to bypass security features and execute payloads without user warnings," Trend Micro theorized. The attacks culminate in the deployment of either MiniDoor, an Outlook email stealer, or a collection of interconnected malware components collectively known as PRISMEX, so named for the use of a steganographic technique to conceal payloads within image files. These include - PrismexSheet, a malicious Excel dropper with VBA macros that extracts payloads embedded within the file using steganography, establishes persistence via COM hijacking, and displays a decoy document related to drone inventory lists and drone prices after macros are enabled. PrismexDrop, a native dropper that readies the environment for follow-on exploitation and uses scheduled tasks and COM DLL hijacking for persistence. PrismexLoader (aka PixyNetLoader), a proxy DLL that extracts the next-stage .NET payload scattered across a PNG image's ("SplashScreen.png") file structure using a bespoke "Bit Plane Round Robin" algorithm and runs it entirely in memory. PrismexStager, a COVENANT Grunt implant that abuses Filen.io cloud storage for C2. It's worth mentioning here that some aspects of the campaign were previously documented by Zscaler ThreatLabz under the moniker Operation Neusploit. APT28's use of COVENANT, an open-source command-and-control (C2) framework, was first highlighted by the Computer Emergency Response Team of Ukraine (CERT-UA) in June 2025. PrismexStager is assessed to be an expansion of MiniDoor and NotDoor (aka GONEPOSTAL), a Microsoft Outlook backdoor deployed by the hacking group in late 2025. In at least one incident in October 2025, the COVENANT Grunt payload was found to not only facilitate information gathering, but also run a destructive wiper command that erases all files under the "%USERPROFILE%" directory. This dual capability lends weight to the hypothesis that these campaigns could be designed for both espionage and sabotage. "This operation demonstrates that Pawn Storm remains one of the most aggressive Russia-aligned intrusion sets," Trend Micro said. "The targeting pattern reveals a strategic intent to compromise the supply chain and operational planning capabilities of Ukraine and its NATO partners." "The strategic focus on targeting the supply chains, weather services, and humanitarian corridors supporting Ukraine represents a shift toward operational disruption that may presage more destructive activities."
thehackernews.comApr 8, 2026extracted
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign
The Russia-linked threat actor known as APT28 (aka Forest Blizzard) has been linked to a new campaign that has compromised insecure MikroTik and TP-Link routers and modified their settings to turn them into malicious infrastructure under their control as part of a cyber espionage campaign since at least May 2025. The large-scale exploitation campaign has been codenamed FrostArmada by Lumen's Black Lotus Labs, with Microsoft describing it as an effort to exploit vulnerable home and small office (SOHO) internet devices to hijack DNS traffic and enable passive collection of network data. "Their technique modified DNS settings on compromised routers to hijack local network traffic to capture and exfiltrate authentication credentials," Black Lotus Labs said in a report shared with The Hacker News. "When targeted domains were requested by a user, the actor redirected traffic to an attacker-in-the-middle (AitM) node, where those credentials were harvested and exfiltrated. This approach enabled a nearly invisible attack that required no interaction from the end user." The infrastructure associated with the campaign has been disrupted and taken offline as part of a joint operation in collaboration with the U.S. Department of Justice (DoJ), Federal Bureau of Investigation (FBI), and other international partners. In a press statement announcing the court-authorized technical operation neutralizing the U.S. portion of the network, the U.S. DoJ said the DNS hijacking operation allowed Russian intelligence agencies to target individuals of interest to the Kremlin, including those in the military, government, and critical infrastructure sectors. The law enforcement effort has been codenamed Operation Masquerade. The activity is assessed to have commenced as far back as May 2025 in a limited capacity, followed by widespread router exploitation and DNS redirection commencing in early August. At its peak in December 2025, more than 18,000 unique IP addresses from no less than 120 countries were found communicating with APT28 infrastructure. These efforts primarily singled out government agencies, such as ministries of foreign affairs, law enforcement, and third-party email and cloud service providers across North African, Central American, Southeast Asian, and European countries. The Microsoft Threat Intelligence team, in its analysis of the campaign, attributed the activity to APT28 and its sub-group tracked as Storm-2754. The tech giant said it identified more than 200 organizations and 5,000 consumer devices impacted by the threat actor's malicious DNS infrastructure. "For nation-state actors like Forest Blizzard, DNS hijacking enables persistent, passive visibility and reconnaissance at scale," Redmond said. "By compromising edge devices that are upstream of larger targets, threat actors can take advantage of less closely monitored or managed assets to pivot into enterprise environments." The DNS hijacking activity has also facilitated AitM attacks that made it possible to facilitate the theft of passwords, OAuth tokens, and other credentials for web and email-related services, putting organizations at risk of broader compromise. The development marks the first time the adversarial collective has been observed using DNS hijacking at scale to support AiTM of Transport Layer Security (TLS) connections after exploiting edge devices, Microsoft added. At a high level, the attack chain involves APT28 gaining remote administrative access to SOHO devices and changing default network configurations to use DNS resolvers under its control. The malicious reconfiguration causes the devices to send their DNS requests to actor-controlled servers. This, in turn, causes DNS lookups for email applications or login pages to be resolved by the malicious DNS server. The threat actor then attempts to conduct AitM attacks against those connections to steal user account credentials by tricking the victims into connecting to malicious infrastructure. Some of these domains are associated with Microsoft Outlook on the web. Microsoft said it also identified AitM activity aimed at non-Microsoft hosted servers in at least three government organizations in Africa. "It is believed that the DNS hijacking operations are opportunistic in nature, with the actor gaining visibility of a large pool of candidate target users then filtering down users at each stage in the exploitation chain to triage for victims of likely intelligence value," the U.K. National Cyber Security Centre (NCSC) said. APT28 is said to have exploited TP-Link WR841N routers for its DNS poisoning operations by likely taking advantage of CVE-2023-50224 (CVSS score: 6.5), an authentication bypass vulnerability that could be used to extract stored credentials via specially crafted HTTP GET requests. Per the DoJ, threat actors affiliated with Military Unit 26165 of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU) have exploited known security vulnerabilities to steal credentials for thousands of TP-Link routers worldwide since at least 2024, using them to redirect DNS requests to GRU-controlled servers. "The actors then implemented an automated filtering process to determine which DNS requests were of interest and warranted interception," the DoJ said. "For select targets, the GRU's DNS resolvers provided fraudulent DNS records for specific domains that mimicked legitimate services – including Microsoft Outlook Web Access – to facilitate Actor-in-the-Middle attacks against encrypted victim network traffic." According to the FBI, APT28 "indiscriminately compromised" a broad set of U.S. and global victims and then filtered down impacted users, particularly targeting information related to military, government, and critical infrastructure. A second cluster of servers has been found to receive DNS requests via compromised routers and subsequently forward them to remote actor-owned servers. This cluster is also assessed to have engaged in interactive operations targeting a small number of MikroTik routers located in Ukraine. "Forest Blizzard's DNS hijacking and AitM activity allows the actor to conduct DNS collection on sensitive organizations worldwide and is consistent with the actor's longstanding remit to collect espionage against priority intelligence targets," Microsoft said. "Although we have only observed Forest Blizzard utilizing their DNS hijacking campaign for information collection, an attacker could use an AiTM position for additional outcomes, such as malware deployment or denial of service."
thehackernews.comApr 7, 2026extracted
Stolen Logins Are Fueling Everything From Ransomware to Nation-State Cyberattacks
Like an inverted pyramid, the range of different attack modes are now built on top of the single point of identity abuse. Stolen credentials are a major threat. Legitimate credentials illegitimately acquired provide legitimate access to illegitimate actors. Once inside the network, these bad actors have greater ability to move and act in stealth. The continuing rise in ransomware attacks bears testament. The theft and resale of credentials operates on an industrial scale. Fueled by the rise of increasingly more sophisticated infostealers, stolen credentials are packaged into ‘logs’ and sold to criminals on the black market. Ontinue reports, “Listings tied to LummaC2 alone surged by 72%, with high-privilege cloud console credentials selling for $1,000–$15,000+.” Ransomware has been one of the primary beneficiaries of stolen credentials. More than 7,000 incidents and 129 active groups were tracked through 2025. At the same time, ransom payments decreased slightly from $892M in 2024 to $820M in 2025. This apparent contradiction is actually logical. “Larger targets, with larger payout potential, will have seen the most aggressive corporate investment (process and technology) mitigating exposure to this attack pattern,” explains Trey Ford, chief strategy and trust officer at Bugcrowd. These larger targets are also more susceptible to government pressure to not pay ransoms, and ransomware income has consequently declined. The ransomware groups have responded with more attacks demanding smaller payments from more but smaller companies. These bad actors have simultaneously increased the pain threshold. Theft of data for blackmail has been growing for several years but is now often supplemented with operational disruption. “Beyond encrypting endpoints, attackers disrupt the ability to operate by wiping systems, deleting backups, sabotaging virtualization, attacking OT/ICS-adjacent services, or breaking identity/administration planes.” Think of modern ransomware as a multi-layer extortion machine, it continues. “Even when victims avoid paying, they are still dealing with downtime, regulatory exposure, third-party disruption, and long recovery cycles.” Nathaniel Jones, VP of security & AI strategy, and field CISO at Darktrace, adds, “Rather than relying solely on encrypting a target’s data for ransom, threat actors will increasingly employ double or even triple extortion strategies, encrypting sensitive data but also threatening to leak or sell stolen data.” At the same time, adversarial use of AI to assist in attacks is growing. Sophisticated and compelling phishing attacks are already evident, but Ontinue has also seen “the first meaningful signs of LLM-assisted malware development in 2H 2025.” This isn’t yet autonomous malware, but are signs that attackers are using AI to assist malware development for speed and features. “LLMs didn’t write the malware, but they wrote large pieces of it,” says Ontinue. “This lowers the bar dramatically. Adversaries with minimal engineering ability now ship tools that look more professional but still contain fundamental security flaws.” Stolen credentials are also fueling supply chain and SaaS attacks. The two big examples from 2025 are the Salesloft Drift OAuth campaign (with more than700 victim organizations) and the Shai-Hulud npm worm. Both campaigns abused the trust necessary in modern business infrastructure, with that trust breached by legitimate but stolen credentials. The increase in global geopolitical tension has further increased and complicated the cybersecurity battlefield – and has probably decreased any remaining ‘honor among thieves’. The Shai-Hulud actor (financially motivated rather than nation state motivated), for example, may attempt to delete the target’s home directory if it finds little to harvest. “This nihilistic ‘scorched earth’ fallback is new and signals the author’s willingness to cause irreversible damage,” notes Ontinue. Such behavior has traditionally been associated with nation state political motivations. This is widening. It is no longer government against government: targets now include civilian entities while attackers include politically motivated citizens as well as elite nation state actors. Ontinue quotes three examples: North Korea’s Lazarus Group $1.5B cryptocurrency theft; wiper attacks targeting Polish civilian infrastructure by Ghost Blizzard; and record-setting DDoS activity peaking at 31.4 Tbps via botnets with more than 500,000 IPs. There is little sign that geopolitically motivated attacks are likely to decrease in the immediate future – they are more likely to increase. Prompted by the US/Israel war against Iran, Iranian actors used wipers in the attack against Stryker earlier this year. The base of this inverted pyramid of malicious activity is occupied by infostealers fueling the activity. Infostealers are a successful tool for malicious actors. They use social engineering to get installed. Industry is yet to find a successful method to prevent social engineering, so it is unlikely that we will be able to stop infostealers. The implication is organizations should assume that attackers have or will obtain legitimate identities to use in their attacks. This means that more energy must be applied to recognizing and blocking the misuse of credentials while in use rather than simply trying to prevent their theft. “To combat today’s new era of threats, driven by the force multiplier of AI, we need to embrace a new approach of adaptive identity,” says Mark McClain, CEO at SailPoint. “Modern identity tools need to be able to discern between regular user activity and abnormal activity, and grant – or deny – access accordingly. Every access decision is driven by who or what the identity is, the context of the data they touch, and the security signals surrounding them. By unifying identity, security, and data contexts, businesses can make real-time decisions to mitigate risk without disrupting operations.” Ontinue summarizes this. “The organizations that will succeed in this new landscape will not necessarily be those with the strongest perimeters, but those that rethink how security is applied across identity. This means treating identity as the core control plane, monitoring authentication activity as closely as endpoint behavior, and securing both human and non-human identities with equal rigor.” Related: AI Speeds Attacks, But Identity Remains Cybersecurity’s Weakest Link Related: Iran Readied Cyberattack Capabilities for Response Prior to Epic Fury Related: Shadow AI Risk: How SaaS Apps Are Quietly Enabling Massive Breaches Related: 136 NPM Packages Delivering Infostealers Downloaded 100,000 Times
securityweek.comMar 31, 2026extracted
Exploitation of Critical Fortinet FortiClient EMS Flaw Begins
Threat actors have started exploiting a critical-severity vulnerability in Fortinet FortiClient EMS, threat intelligence firm Defused Cyber warns. A centralized management server, FortiClient EMS allows organizations to deploy, configure, and monitor FortiClient endpoints across their environments. It also supports multi-tenant deployments, enabling the management of multiple customer sites from a single instance. Tracked as CVE-2026-21643, the now-exploited bug is described as an SQL injection issue that can be exploited remotely, without authentication, via specially crafted HTTP requests. Successful exploitation of the flaw, Fortinet notes in its advisory, could lead to arbitrary code or command execution. The security defect impacts FortiClient EMS version 7.4.4 and was patched in early February in version 7.4.5. According to Fortinet, the vulnerability was discovered internally. One month after public disclosure, cybersecurity firm Bishop Fox published technical information on the bug, warning that it was practical to exploit. “Our analysis shows attackers can abuse the publicly accessible /api/v1/init_consts endpoint to trigger the SQL injection before authentication. Because this endpoint returns database error messages and has no lockout protections, attackers can rapidly extract sensitive data from vulnerable FortiClient EMS 7.4.4 multi-tenant deployments,” Bishop Fox warned. The issue, the cybersecurity company said, was introduced in version 7.4.4 through a redesigned middleware stack and database connection layer that resulted in HTTP identification headers being passed to a database query without sanitization, before authentication. This enables an attacker to execute arbitrary SQL code against the database and access admin credentials, endpoint inventory, security policies, and endpoint certificates. Proof-of-concept (PoC) code targeting the vulnerability has been published online. Over the weekend, Defused warned that CVE-2026-21643 had been exploited for at least four days and that roughly 1,000 FortiClient EMS deployments are exposed to the internet. As of March 30, The Shadowserver Foundation tracks over 2,000 internet-accessible instances. It is unclear how many of the exposed deployments are vulnerable, and Fortinet has yet to update its advisory to flag the bug as exploited. SecurityWeek has emailed Fortinet for a statement on the flaw’s exploitation and will update this article if the company responds. Related: StrongSwan Flaw Allows Unauthenticated Attackers to Crash VPNs Related: Russian APT Star Blizzard Adopts DarkSword iOS Exploit Kit Related: Exploitation of Fresh Citrix NetScaler Vulnerability Begins Related: F5 BIG-IP DoS Flaw Upgraded to Critical RCE, Now Exploited in the Wild
securityweek.comMar 31, 2026extracted
日本企業は10年で「VPN 2.0」を導入しただけ 「ゼロトラストごっこ」を終わらす現実的な生存戦略
2025�N11��26���J�ẤuITmedia Security Week 2025 �H�v�ŁA�p�����S ����� �� �ō��Z�p�ӔC�� �ђB�玁���u�[���g���X�g�̐^�̈Ӌ�Ƃ��̊� ��[���g���X�g���ۂ��Ƃ̌��ʁ�v�Ƒ肵�ču�������B ���̋L���͉������ł��B����o�^�i�����j����ƑS�Ă������������܂��B �@�ю��́A����܂ő����̊�ƁE�g�D�̃Z�L�����e�B��ɁA�F�E�F��A�C�f���e�B�e�B�[�iID�j�Ǘ��𒆐S�Ɋւ���Ă����B�o�ώY�Ə� �������� ���v���W�F�N�g���i2020�2022�N�j�ɂ��ݐЂ��A���݂̓f�W�^���� �A�C�f���e�B�e�B�A�[�L�e�N�g�^�A�C�f���e�B�e�B���j�b�g ���j�b�g�������߂Ă���B�c����m��w ��w�@ ���f�B�A�f�U�C�������ȁiKMD�j������m�ے��ŁA����w��KMD������ �����ł�����B �@�u���g�D�̃V�X�e���͍��A�N������Ă��Ȃ��B�����f�����āA���S���Ė���Ă��܂����H�v�Ƃ����₢����n�܂����{�u���ŗю��́A���{�̑����̊�ƁE�g�D���ׂ��Ă���u�[���g���X�g�������v�ɑ��錵����������w�E�B�{������ׂ��Ɉڂ邽�߂ɁA�Z�p�ɉ����ċZ�p�ҁA�o�c�҂��ǂ̂悤�Ɏ����ϗe������K�v�����邩����������B�{�e�ł́A�u�����e��v��B �@�ю��́u�����͊��ɐN������Ă���v�Ƃ����O��ɗ��ׂ����Ǝ咣����B���̗����������A�[���g���X�g�Z�L�����e�B�ւ̑����Ȃ̂��Ƃ����B�ю��́A�{���I�ȉ��v�ɂ́u�g�D�̏d�v�T�[�o���C���^�[�l�b�g�ɒ��ځA���Œu���܂����H�v�Ƃ����₢�ɓ������邩�ɂ���Ƒ�����B���A�����Ȃ��Ă��Ȃ����R�͗��j��������Ă���B �@�u�[���g���X�g�v�Ƃ����l�������K�v�ɂȂ����w�i�ɂ́A�]���́u���E�h��v�^���f�������{���畢�����A���X�̏d��ȃZ�L�����e�B�C���V�f���g�����݂���B�ю��́A���j�Ɏc��悤�ȍU����������n��ŕ��͂��A���ꂼ�ꂪ����̃Z�L�����e�B�A�[�L�e�N����ɂǂ̂悤�ȋ��P�������炵�������������B �@2009�N�AGoogle���͂��߂Ƃ��鑽���̃e�b�N��Ƃ��W�I�ɂȂ����uOperation Aurora�v�́A��x�����l�b�g���[�N�ւ̐N�����������U���҂��u�M�����ꂽ���K�]�ƈ��v�Ƃ��ĐU�镑���A���������R�Ɉړ��i���e�������[�u�����g�j�ł��������𔒓��̉��ɂ��炵���B���̎������˂��t�������P�͋��E�h��̎��ł���A�u�ǂ̓����́A�����Ĉ��S�ł͂Ȃ��v���Ƃ�\�����̂������B �@���ɐ��E��k���������̂́A�U���҂�MSP�i�}�l�[�W�h�T�[�r�X�v���o�C�_�[�j�Ƃ̐M���W�����p���A�����e�i���X�pVPN�iVirtual Private Network�j�ڑ��Ƃ����u�����v����ڋq�l�b�g���[�N�ɐN�������uOperation Cloud Hopper�v���B�uA�Ђ�B�Ђ�M�����Ă��邩��Ƃ����āAB�Ђ���̃p�P�b�g�����ɐM�p���Ă͂Ȃ�Ȃ��v�Ƃ����T�v���C��F�[���U���ɂ�����d�v�ȋ��P�u�M���͐��ڂ��Ȃ��v���m�����ꂽ�B �@���ݐi�s��ő����uVolt Typhoon�v�́A�}���E�F�A���g�킸�AOS�W���c�[���݂̂𗘗p����uLiving off the Land�v�i���ALotL�j��p�ƁA��������SOHO���[�^�[�Q�ݑ�ɂ��邱�ƂŁu��ʉƒ납��̃A�N�Z�X�v�ɋU������I���Ȏ����g�ݍ��킹��B �@�]���̌��m��@�����͉������Volt Typhoon�ɑ��A�ю��́u�Ȃ����̃��[�U�[���A�[��ɉƒ�p���[�^�[�o�R��PowerShell�����s���Ă���̂��H�v�Ƃ������A�R���e�L�X�g�ُ̈�𗝉����邱�Ƃ̏d�v������������B �@Salt Typhoon�����ݐi�s��̋��Ђ��BAT&T��Verizon�ALumen�Ƃ�����ISP�i�C���^�[�l�b�g�T�[�r�X�v���o�C�_�[�j�̃R�A�l�b�g���[�N�A�����Cisco Systems�����[�^�[���^�[�Q�b�g�ɁA�Ǝ�i�������Ⴍ�j����˂����ƂŃ��[�^�[���x���Ńg���t�B�b�N���~���[�����O���A�U���҂̃T�[�o�ɓ]��������B �@�u�G���h�|�C���g��T�[�o�ł͂Ȃ��A�������Ȃ��y�ǁi�l�b�g���[�N�j���̂��̂��������ꂽ�B�o�b�N�h�A�i���@�I�T��j���̂��U���҂̃o�b�N�h�A�Ƃ��ċ@�\�����ň��̃P�[�X�BISP��l�b�g���[�N�@�킷��M�p�ł��Ȃ��B�A�v���P�[�V�����w�iL7�j�ł̃G���h�c�[�G���h�Í����iALTS�FApplication Layer Transport Security�j�Ƒ��ݔF�imTLS�FMutual Transport Layer Security�j�ȊO�ɖh���͂Ȃ��v�i�ю��j �@�ߔN�A�U���̎����ID��Ղ��̂��̂Ɉڂ��Ă���B�uStorm-0558�v�ł�Microsoft�̏��������ގ悳��A�uMidnight Blizzard�v�ł�MFA�i���v�f�F�FMulti-Factor Authentication�j���ݒ�̃e�X�g�����N�_�ɁA�{�Ԋ��́uMicrosoft 365�v�ւ̃t���A�N�Z�X�����������ӂ���OAuth�A�v�����쐬���ꂽ�B����ꂪ�ˑ�����IDaaS�iIdentity as a Service�j���̂��P���Q�_�ɂȂ蓾��Ƃ��������́A�uIDaaS�Ȃ���S�v�Ƃ�������̏I���������Ă���Ɨю��͎w�E����B �@�����̎����͑Ί݂̉Ύ��ł͂Ȃ��B�u���J�Î��i2025�N11���j�ł��V�X�e���ɉe�����c���Ă����A�T�q�O���[�v�z�[���f�B���O�X�iHD�j�̃C���V�f���g�ł́A�N��������s�܂łɖ�17�J�����̒����Ԑ�������Ă����\�����w�E����Ă���B����͌��݂̓��{�ɂ����鋫�E�h��̎��Ԃ̈�[���B�ю��͌x���������炷�B �@�u�U���҂�1�N�ȏ�A���Ȃ��̏]�ƈ��ׂ̗ő�����߂Đ������Ă��邩������Ȃ��v �@�����̗��j�I�C���V�f���g�́A�����̃Z�L�����e�B���f���������Ɍ��E�ɒB���Ă��邩�������Ă���B�ǂɎ��ꂽ�u�����v�͂��͂⑶�݂��Ȃ��B���̌����F���������A�[���g���X�g�̐^�̒��𗝉�����o���_�ƂȂ�B �@���E�h��̍\���I�s�k��Ɋ�����Google�́AOperation Aurora���@�ɁuBeyondCorp�v�Ƃ����V���ȃZ�L�����e�B���f���̍\�z�ɒ��肵���B�ю��ɂ��A�����Google�ɂƂ��Ắu���������v�ł���A�P�Ȃ鐻�i�����ł͂Ȃ��A�Z�L�����e�B�N�w�̍��{�I�ȕϊv�������Ƃ����B �@�����ł́uCorp�v�͈�ʖ����ł͂Ȃ��BGoogle�Г��ɑ��݂��������C���g���l�b�g�ucorp.google.com�v�Ƃ����ŗL�������w���B���āA���̃l�b�g���[�N�̓����ɂ���ΎГ��̂�����Ɩ��A�v���ɃA�N�Z�X�ł��鐹�悾�����BGoogle�����������f�́A���̐���̊��S�Ȕp�~���B �@Google�͎Г�LAN���A�J�t�F�̌��OWi-Fi�ȂǂƓ����́A��ؐM���ł��Ȃ��l�b�g���[�N�ɒu���������B����ɂ��A�A�N�Z�X����̊�_�́u�ꏊ�v�iIP�A�h���X�j����uID�ƃf�o�C�X�̏�ԁv�i�R���e�L�X�g�j�ւƊ��S�Ɉڍs���ꂽ�B���̌��ʁAVPN�͑S�p����A�S�Ẵ��N�G�X�g���ʂɌ�����Identity-Aware Proxy�iIAP�j���A�v���P�[�V�����̎�O�ɔz�u���ꂽ�B �@�u�����̏��݂��w�l�b�g���[�N�x����wID�x�Ɉړ]������A�[�L�e�N����̍\�����v�������[���g���X�g�̖{�����v �@�[���g���X�g�Ƃ������t�����{�ŕ��y���Ă���10�N�B�������A�ю��͂��̎����̑������{�����猜�����ꂽ�u�[���g���X�g�������v�ɂƂǂ܂��Ă���ƌ������w�E����B �@�����̓��{��Ƃ���������ZTNA�i�[���g���X�g�l�b�g���[�N�A�N�Z�X�j���i�̎��Ԃ́A�C���o�E���h�|�[�g����������́uVPN 2.0�v�ɉ߂��Ȃ��P�[�X���U�������Ɨю��B�g���l���Z�p�ŎГ��l�b�g���[�N���������Ă��邾���ł���A��x�N�����������e�������[�u�����g�̃��X�N�͑S����������Ă��Ȃ��B �@�u�|���V�[���w10.0.0.0/8 Permit�x�Ȃ�A����̓N���E�h�o�R�̋����LAN�ł����Ȃ��v�i�ю��j �@�����������P�[�X�ł́A���[����肪��������Ă���B�uIDaaS����ꂽ������S�v�uSWG�iSecure Web Gateway�j��CASB�iCloud Access Security Broker�j�����Ă����Α��v�v�Ƃ������A���i�����ɂ��v�l��~���B �@�uID�����͑O�i�����A�f�o�C�X�̏�Ԃ����Ă��Ȃ��B�R���e�L�X�g���l�����Ȃ���Ζ��͂ȕ������c��B�o����͂��Ă��A�����ʐM�����@�n�т̂܂܂ł́A���������U���҂̊����������Ă��܂��B�����͋Z�p�I���̌p�����v �@�ł́A�Ȃ������̑g�D�́A�A�[�L�e�N����̕ϊv�ł͂Ȃ��A���Ղȃt�@�C�A�E�H�[���ɓ�������ł����̂��낤���B�ю��́A�u������̖₢�u�g�D�̏d�v�T�[�o���C���^�[�l�b�g�ɒ��ځA���Œu���܂����H�v�ɐG��A���̗��j�I�w�i���l�@����B �@���āASELinux��Network Access Control�AHost-based IPS�iIntrusion Prevention System�j�Ƃ������z�X�g���S�i����낤�j���Z�p�͑��݂������A���̕��G���Ɖ^�p���ׂ̍������猻��Ō�[�����Ă������B���̉ߋ��̎��s���A���E�h��^�Ƃ���������₷���Z�L�����e�B���f���ւ̐[�������I�ˑ��݁A�����̋Z�p�I�����i�������Ă���B �@����E�p���A�����I�Ȉ���ݏo���ɂ́A���z�_�ł͂Ȃ���̓I�Ȑ헪�����߂���B �@�S�]�ƈ��ɍ����ȃ��C�Z���X��t�^�������S�Ǘ��[����z�z����\�\Google���u�k�ɐ��v�ƕ\������悤�ȗ��z�I�ȃ[���g���X�g�́A�����̓��{��ƂɂƂ��Ĕ��I���B�������A�ю��́u���߂�K�v�͂Ȃ��v�ƌ��A�R�X�g�ƕ����̕ǂ��z���邽�߂̌����I�ȃA�v���[������B �@�܂��������ׂ��́A�R�X�g���ABYOD�iBring Your Own Device�j�ɂ�����v���C�o�V�[�ւ̒�R���A������MDM�iMobile Device Management�j��EDR�iEndpoint Detection and Response�j�̖���������3���B �@���ɁuEDR����ꂽ����MDM�͕s�v�v�Ƃ����uEDR�_�b�v�́u�v���I�Ȍ�����v�Ɨю��BMDM�́u�˒��܂�v�i�\�h�j�ł���AEDR�́u�Ď��J�����v�i����Ή��j���B�Ď��J�����������Ă��˒��܂肪�Ȃ���ΓD�_�͓������ł���AEDR�����ł͐�q��LotL�U���ɂ͖��͂��B�����āATPM�iTrusted Platform Module�j�Ƃ������n�[�h�E�F�A�ł̖h����K�v�ɂȂ�B �@�R�X�g��v���C�o�V�[�AEDR�_�b�̖����������邽�߂ɗю��������̂��A�u�M���̊K�w���v�Ƃ��������I�Ȑ����헪���B����́AGoogle�́uTrust Tiers�v���f�����Q�l�ɁA�f�o�C�X�̊Ǘ����x���ɉ����ăA�N�Z�X����������A�v���[����B �@�[���g���X�g�̊T�O�́A���͂�]�ƈ��̃A�N�Z�X�iBeyondCorp�j�����ɂƂǂ܂�Ȃ��B�u�k�ɐ��͈ړ������v�Ɨю��͌��A�h�q�����N���E�h�l�C�e�B�u���ɂ�����T�[�r�X�ԒʐM�Ɋg�����ꂽ�uBeyondProd�v�̐��E����������B �@BeyondProd�Ƃ́A�f�[�^�Z���^�[�����ł���M�������A�}�C�N���T�[�r�X�Ԃ̒ʐM�i���[�N���[�hID�j�������郂�f�����BIP�A�h���X���Ӗ��𐬂��Ȃ��Ȃ����R���e�i���ŏd�v�Ȃ̂́u�ǂ�IP���v�ł͂Ȃ��u�ǂ̃��[�N���[�h���v�u�ǂ̃R�[�h���v����肷�邱�Ƃ��B �@���̎����W���Ƃ��āA�ю���Cloud Native Computing Foundation�iCNCF�j�̃v���W�F�N�g�uSPIFFE/SPIRE�v�iSecure Production Identity Framework for Everyone/SPIFFE Runtime Environment�j���Љ���B�v���b�g�t�H�[���Ɉˑ������A�����郏�[�N���[�h�Ɍ��؉\��ID�I�ɕt�^����I�[�v���Ȏd�g�݂��B �@����ɖ����ɖڂ�������ƁA���U����ID�Ǘ��@�\��A�g������uIdentity Fabric�v�Ƃ����T�O��A�����I�Ƀ^�X�N�����s����AI�i�l�H�m�\�j�G�[�W�F���g���̂�ID��t�^����l�����ANIST�i�č����W���Z�p�������j���f������̉�����OpenID Foundation�ɂ��AuthZEN�iAuthorization Exchange�j��SSF�iShared Signals Framework�j�Ƃ������W���d�l�ȂǁAID�Ǘ��͂�蓮�I�����ݐڑ����ꂽ���E�Ɍ������Ă���B �@�u���̍Ō�ɁA�ю��̓[���g���X�g���f���ւ̈ڍs�ɂ�����A����ׂ��p���Ƃ��āA�G���W�j�A�����O�̐��E����2�̌��t�����p�����B �@1�ڂ́A�G�N�X�g���[���v���O���~���O�iXP�j�̒҃P���g�E�x�b�N���́uEmbrace Change�v�i�ω�����i����j���B���Ђ�����₦���ω����钆�ŁA�Œ�I�ȁu�ǁv�ɌŎ�����̂ł͂Ȃ��AID�ƃR�[�h���j�Ƃ��āA�ω��ɂ��Ȃ₩�ɑΉ��ł���\���ւƎ����ϗe�����Ă����K�v������B �@2�ڂ́A�\�t�g�E�F�A�J���҂̃W���G���E�X�|���X�L�[���́uFire and Motion�v�i�ˌ����O�i�j�B���z�͉�����������Ȃ����A�͍��̒��ŗ����~�܂��Ă�������ꌂ����Ă��܂��B�����Ȍv���҂̂ł͂Ȃ��A�����̃Z�L�����e�B��Ŏ��Ԃ��҂��Ȃ���A���̗��ŏ������ł��Z�p�I����ԍς��A�A�[�L�e�N����̖{���I�ȉ��P��i�߂�ׂ����B �@�Ō�ɁA�ю��́u�w�[���g���X�g���ۂ��x���瑲�Ƃ��A�wBeyondCorp�x�Ɋw�сA�C���^�[�l�b�g�ɐ������Ȃ���x�o��������Ăق����v�ƌĂъ|����B���̐�ɂ����A�u������̖₢�ɑ���^�̓����A���Ȃ킿�u�{���Ɉ��S���Ė����v��Ԃ��҂��Ă���̂��B �@�ю��́A����܂ł�ITmedia Security Week�Łu�F�v���e�[�}�ɉ��x���u�����Ă���B����ҏW���ł́A���̔F�̏d�v����ʊp�x����œ_�Ă�ׂ��A�[���g���X�g���e�[�}�ɂ����u�����˗������B���͂�[���g���X�g�ƔF�E�F�͂قړ��`�ł���A���m�E�Ή������ł͂Ȃ��h��̎��_�ł��d�v�������܂��Ă���B�������AIDaaS�̗��p���S�[���ł͂Ȃ��B�ю��ɂ́A���̎����J�ɉ�����Ă����������B �@���i�̓������Z�L�����e�B����̒��S�ł͂Ȃ��Ȃ������A�܂��͍�����ꂽ�悤�ȍl�����ւƈӎ������߂邱�Ƃ������A��ƁE�g�D���ł���u�ˌ����O�i�v�̑����ɂȂ�g�s���h�Ȃ̂ł͂Ȃ����낤���B Copyright © ITmedia, Inc. All Rights Reserved.
atmarkit.itmedia.co.jpMar 30, 2026extracted
Russian APT Star Blizzard Adopts DarkSword iOS Exploit Kit
A Russian state-sponsored hacking group tracked as Star Blizzard has adopted the DarkSword iOS exploit kit in an ongoing campaign, Proofpoint reports. On Friday, investigation platform Malfors warned that a Russian threat actor has been using Atlantic Council lures in an email campaign delivering the DarkSword-linked GhostBlade malware. Shortly after, Proofpoint attributed the campaign to Star Blizzard, an APT associated with the Russian intelligence service FSB and which is also tracked as Callisto, ColdRiver, SeaBorgium, and TA446. According to the cybersecurity firm, the messages were observed on March 26 and originated from multiple compromised sender addresses. Over the past two weeks, Proofpoint says, Star Blizzard has significantly increased the volume of malicious emails compared to its normal operational tempo. The March 26 activity represented a similar spike in volume and marked another shift in attack tradecraft: the emails contained links instead of malicious attachments. “Proofpoint automated analysis was redirected to a benign decoy PDF, likely because of server-side filtering to only redirect iPhone browsers to the exploit kit,” the cybersecurity firm says. It also notes that it has found evidence that Star Blizzard has added the DarkSword iOS exploit kit to its arsenal, pointing out that this is the first time the APT has been seen targeting iCloud accounts and Apple devices. The evidence, Proofpoint notes, includes a DarkSword loader uploaded to VirusTotal that references a second-stage domain associated with the hacking group, and a submission on @URLScan showing the use of the exploit. The known Star Blizzard domain was “serving the DarkSword exploit kit, including the initial redirector, exploit loader, RCE, and PAC bypass components. The sandbox escapes were not observed,” Proofpoint says. The cybersecurity firm has not observed the exploit kit’s delivery, but believes that the Russian APT has adopted it for credential harvesting and intelligence collection after someone leaked it on GitHub. The Atlantic Council-themed campaign has targeted financial, government, higher education, and legal entities, as well as think tanks, “indicating that this new capability led TA446 to attempt to use DarkSword opportunistically against a broader target set,” Proofpoint notes. Related: Coruna iOS Exploit Kit Likely an Update to Operation Triangulation Related: Russian APT Exploits Zimbra Vulnerability Against Ukraine Related: Ex-US Defense Contractor Executive Jailed for Selling Exploits to Russia
securityweek.comMar 30, 2026extracted
TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
Proofpoint has disclosed details of a targeted email campaign in which threat actors with ties to Russia are leveraging the recently disclosed DarkSword exploit kit to target iOS devices. The activity has been attributed with high confidence to the Russian state-sponsored threat group known as TA446, which is also tracked by the broader cybersecurity community under the monikers Callisto, COLDRIVER, and Star Blizzard (formerly SEABORGIUM). It's assessed to be affiliated with Russia's Federal Security Service (FSB). The hacking group is known for spear-phishing campaigns aimed at harvesting credentials from targets of interest. However, attacks mounted by the threat actor over the past year have targeted victims' WhatsApp accounts, as well as leveraged various custom malware families to steal sensitive data. The latest activity, highlighted by Proofpoint and Malfors, involves using fake "discussion invitation" emails spoofing the Atlantic Council to facilitate the delivery of GHOSTBLADE, a dataminer malware, via the DarkSword exploit kit. The emails were sent from compromised senders on March 26, 2026. One of the email recipients was Leonid Volkov, a prominent Russian opposition politician and the political director of the Anti-Corruption Foundation. An automated analysis triggered by Proofpoint's security tools is said to have redirected to a benign decoy PDF document, likely because of server-side filtering put in place to only lead iPhone browsers to the exploit kit. "We have not previously observed TA446 target users' iCloud accounts or Apple devices, but the adoption of the leaked DarkSword iOS exploit kit has now enabled the actor to target iOS devices," Proofpoint said. The enterprise security firm also noted that the volume of emails from the threat actor has been "significantly higher" in the last two weeks, adding that these attacks lead to the deployment of a known backdoor referred to as MAYBEROBOT via password-protected ZIP files. The group's use of DarkSword has also been corroborated by the fact that a DarkSword loader uploaded to VirusTotal has been found to reference "escofiringbijou[.]com," a second-stage domain attributed to the threat actor. A urlscan.io result has revealed that the TA446-controlled domain has served the DarkSword exploit kit, including the initial redirector, exploit loader, remote code execution, and Pointer Authentication Code (PAC) bypass components. However, there is no evidence that sandbox escapes were delivered. It's suspected that the TA446 is repurposing the DarkSword exploit kit for credential harvesting and intelligence collection, with Proofpoint noting that the targeting observed in the email campaign was "much wider than usual" and that it included government, think tank, higher education, financial, and legal entities. This, in turn, has raised the possibility that the threat actor is leveraging the new capability afforded by DarkSword as part of an opportunistic campaign against a broader target set. Greg Lesnewisch, staff threat researcher at Proofpoint, told The Hacker News that the attack likely leveraged a leaked version of DarkSword, which was taken directly from one of UNC6353's watering holes and uploaded to GitHub, and that "TA446 is using the same version of the exploit kit UNC6353 was using." It's currently not known if any of these attacks were successful. However, Proofpoint said all messages targeting its customers were blocked. The development comes as Apple has begun sending Lock Screen notifications to iPhones and iPads running older versions of iOS and iPadOS to alert users of web-based attacks and urging them to install the update to block the threat. The unusual step signals that the company is treating it as a broad enough threat requiring users' immediate attention. Apple's warning also coincides with the leak of a new version of DarkSword on GitHub, raising concerns that they could democratize access to nation-state exploits, fundamentally shifting the mobile threat landscape. Justin Albrecht, principal researcher at Lookout, said the leaked, plug-and-play version allows even unskilled threat actors to deploy the advanced iOS espionage kit, turning it into commodity malware. "DarkSword refutes the common belief that iPhones are immune to cyber threats, and that advanced mobile attacks are only used in targeted efforts against governments and high-ranking officials," Albrecht added.
thehackernews.comMar 28, 2026extracted
FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks
Threat actors affiliated with Russian Intelligence Services are conducting phishing campaigns to compromise commercial messaging applications (CMAs) like WhatsApp and Signal to seize control of accounts belonging to individuals with high intelligence value, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) said Friday. "The campaign targets individuals of high intelligence value, including current and former U.S. government officials, military personnel, political figures, and journalists," FBI Director Kash Patel said in a post on X. "Globally, this effort has resulted in unauthorized access to thousands of individual accounts. After gaining access, the actors can view messages and contact lists, send messages as the victim, and conduct additional phishing from a trusted identity." It's worth noting that the attacks are designed to break into the victims' CMA accounts through phishing and do not exploit any security vulnerability or weakness to crack the platforms' encryption protections. These entail sending messages engineered to create a false sense of urgency by claiming that suspicious account activity or login attempts from an unrecognized device or location have been detected. While the agencies did not attribute the activity to a specific threat actor, prior reports from Microsoft and Google Threat Intelligence Group have linked such campaigns to multiple Russia-aligned threat clusters tracked as Star Blizzard, UNC5792 (aka UAC-0195), and UNC4221 (aka UAC-0185). In a similar alert, the Cyber Crisis Coordination Center (C4), part of the National Cybersecurity Agency of France (ANSSI), warned of a surge in attack campaigns targeting instant messaging accounts associated with government officials, journalists, and business leaders. "These attacks – when successful – can allow malicious actors to access conversation histories, or even take control of their victims' messaging accounts and send messages while impersonating them," C4 said. The end goal of the campaign is to enable the threat actors to gain unauthorized access to victims' accounts, enabling them to view messages and contact lists, send messages on their behalf, and even conduct secondary phishing against other targets by abusing trusted relationships. As recently alerted by cybersecurity agencies from Germany and the Netherlands, the attack involves the adversary posing as "Signal Support" to approach targets and urge them to click on a link (or alternatively scan a QR code) or provide the PIN or verification code. In both cases, the social engineering scheme allows the threat actors to gain access to the victim's CMA account. However, the campaign has two different outcomes for the victim depending on the method used - If the victim opts to provide the PIN or verification code to the threat actor, they lose access to their account, as the attacker has used it to recover the account on their end. While the threat actor cannot access past messages, the method can be used to monitor fresh messages and send messages to others by impersonating the victim. If the victim ends up clicking the link or scanning the QR code, a device under the control of the threat actor gets linked to the victim's account, allowing them to access all messages, including those sent in the past. In this scenario, the victim continues to have access to the CMA account unless they are explicitly removed from the app settings. To better protect against the threat, users are advised to never share their SMS code or verification PIN with anyone, exercise caution when receiving unexpected messages from unknown contacts, check links before clicking them, and periodically review linked devices and remove those that appear suspicious. "These attacks, like all phishing, rely on social engineering. Attackers impersonate trusted contacts or services (such as the non-existent 'Signal Support Bot') to trick victims into handing over their login credentials or other information," Signal said in a post on X earlier this month. "To help prevent this, remember that your Signal SMS verification code is only ever needed when you are first signing up for the Signal app. We also want to emphasize that Signal Support will *never* initiate contact via in-app messages, SMS, or social media to ask for your verification code or PIN. If anyone asks for any Signal-related code, it is a scam."
thehackernews.comMar 21, 2026extracted
Russian hackers exploit Zimbra flaw in Ukrainian govt attacks
Hackers part of APT28, a state-backed threat group linked to Russia's military intelligence service (GRU), are exploiting a Zimbra Collaboration Suite (ZCS) vulnerability in attacks targeting Ukrainian government entities. This high-severity security flaw (tracked as CVE-2025-66376 and patched in early November) stems from a stored cross-site scripting (XSS) that unauthenticated attackers can exploit to gain remote code execution (RCE) and compromise the Zimbra server and the target's email account. On Wednesday, the Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its catalog of vulnerabilities exploited in the wild. CISA also ordered Federal Civilian Executive Branch (FCEB) agencies to secure their servers within two weeks, as mandated by the Binding Operational Directive (BOD) 22-01 issued in November 2021. While the U.S. cybersecurity agency didn't provide further details on the ongoing exploitation of CVE-2025-66376, security researchers at Seqrite Labs reported a day earlier that the Zimbra XSS vulnerability had been exploited by APT28 military hackers in attacks against Ukraine. The Ukrainian State Hydrology Agency (a critical infrastructure entity under the Ministry of Infrastructure that provides navigational, maritime, and hydrographic support) was one of the targets of this phishing campaign (named Operation GhostMail). "The phishing email has no malicious attachments, no suspicious links, no macros. The entire attack chain lives inside the HTML body of a single email, there are no malicious attachments," Seqrite Labs said. The APT28 (aka Fancy Bear, Strontium) hackers' malicious messages delivered an obfuscated JavaScript payload that exploits the CVE-2025-66376 vulnerability when the recipient opens the email in a vulnerable Zimbra webmail session. "The script executes silently in the browser and begins harvesting credentials, session tokens, backup 2FA codes, browser-saved passwords, and the contents of the victim's mailbox going back 90 days with all the data exfiltrated over both DNS and HTTPS," the researchers added. Zimbra security flaws are frequently targeted in attacks, including by Russian state-sponsored threat groups, and have been used to breach thousands of vulnerable email servers in recent years. For instance, starting in February 2023, the Russian Winter Vivern cyberespionage group used another reflected XSS exploit to breach Zimbra webmail portals and spy on the communications of NATO-aligned organizations and persons, including government officials, military personnel, and diplomats. In October 2024, U.S. and U.K. cyber agencies also warned that APT29 (aka Cozy Bear, Midnight Blizzard) hackers linked to Russia's Foreign Intelligence Service (SVR) were attacking vulnerable Zimbra servers "at a mass scale," exploiting a vulnerability previously used to steal email account credentials. Zimbra is a widely popular email and collaboration software suite used by hundreds of millions of people, including hundreds of government agencies and thousands of businesses worldwide. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 19, 2026extracted
Russia-linked espionage campaign targeting Ukraine using Starlink and charity lures
Russia-linked espionage campaign targeting Ukraine using Starlink and charity lures A relatively new Russia-linked hacker group has launched a cyber-espionage campaign targeting Ukrainian organizations using spyware disguised within documents about Starlink satellite internet terminals and a well-known Ukrainian charity, researchers have found. The campaign, observed in February, deployed a backdoor dubbed DrillApp that allows attackers to upload and download files from infected computers, record audio through a microphone and capture images from a webcam, according to a report by cybersecurity firm Lab52. Researchers attributed the campaign to the Russian-linked hacker group Laundry Bear, also tracked as Void Blizzard, which has been active since at least 2024 and has previously targeted NATO member states and Ukrainian institutions. Ukraine’s computer emergency response team, CERT-UA, previously reported a separate operation by the group targeting the country’s armed forces earlier this year. Researchers said the campaigns relied on similar techniques, including charity-themed lures and hosting malicious components on public text-sharing services. In the latest operation, attackers used documents impersonating requests from Come Back Alive, a Ukrainian charity that supports the armed forces, as well as images related to the verification of Starlink satellite internet terminals. Ukraine introduced a verification system for Starlink terminals earlier in February after authorities confirmed that Russian forces had begun installing the technology on attack drones. Once opened, the malicious file executes through the Microsoft Edge browser, allowing attackers to access the victim’s file system and capture audio from the microphone, video from the camera and recordings of the device’s screen. Researchers say attackers may be using web browsers to deliver malware because browsers often have legitimate access to sensitive device features such as cameras, microphones, and screen recording, which can make malicious activity harder to detect. Browsers are also rarely flagged as suspicious by security tools. Lab52 said the spyware appears to still be in an early stage of development, suggesting the attackers may be experimenting with new methods to evade defenses. Researchers identified two versions of the malware used in the campaign, which differed primarily in the lures used to trick victims. Laundry Bear was previously described as using “relatively simple techniques that can be difficult to detect.” The group is primarily focused on cyber-espionage. Microsoft has previously reported that it has successfully compromised organizations across several sectors in Ukraine, including education, transportation, and defense. Security researchers have also noted overlaps between Laundry Bear’s tactics and those used by the Russian military intelligence threat actor APT28, also known as Fancy Bear, though analysts generally consider them to be distinct actors. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaMar 16, 2026extracted
DRILLAPP Backdoor Targets Ukraine, Abuses Microsoft Edge Debugging for Stealth Espionage
Ukrainian entities have emerged as the target of a new campaign likely orchestrated by threat actors linked to Russia, according to a report from S2 Grupo's LAB52 threat intelligence team. The campaign, observed in February 2026, has been assessed to share overlaps with a prior campaign mounted by Laundry Bear (aka UAC-0190 or Void Blizzard) aimed at Ukrainian defense forces with a malware family known as PLUGGYAPE. The attack activity "employs various judicial and charity themed lures to deploy a JavaScript‑based backdoor that runs through the Edge browser," the cybersecurity company said. Codenamed DRILLAPP, the malware is capable of uploading and downloading files, leveraging the microphone, and capturing images through the webcam by taking advantage of the web browser's features. Two different versions of the campaign have been identified, with the first iteration detected in early February. The attack makes use of a Windows shortcut (LNK) file to create an HTML Application (HTA) in the temporary folder, which then loads a remote remote script hosted on Pastefy, a legitimate paste service. To establish persistence, the LNK files are copied to the Windows Startup folder so that they are automatically launched following a system reboot. The attack chain then displays a URL containing lures related to installing Starlink or a Ukrainian charity named Come Back Alive Foundation. The HTML file is eventually executed via the Microsoft Edge browser in headless mode, which then loads the remote obfuscated script hosted on Pastefy. The browser is executed with additional parameters like –no-sandbox, –disable-web-security, –allow-file-access-from-files, –use-fake-ui-for-media-stream, –auto-select-screen-capture-source=true, and –disable-user-media-security, granting it access to the local file system, as well as camera, microphone, and screen capture without requiring any user interaction. The artifact essentially functions as a lightweight backdoor to facilitate file system access and capture audio from the microphone, video from the camera, and images of the device's screen all through the browser. It also generates a device fingerprint using a technique called canvas fingerprinting when run for the first time and uses Pastefy as a dead drop resolver to fetch a WebSocket URL used for command‑and‑control (C2) communications. The malware transmits the device fingerprint data along with the victim's country, which is determined from the machine's time zone. It specifically checks if the time zones correspond to the U.K., Russia, Germany, France, China, Japan, the U.S., Brazil, India, Ukraine, Canada, Australia, Italy, Spain, and Poland. If that's not the case, it defaults to the U.S. The second version of the campaign, spotted in late February 2026, eschews LNK files for Windows Control Panel modules, while keeping the infection sequence largely intact. Another notable change involves the backdoor itself, which has now been upgraded to allow recursive file enumeration, batch file uploads, and arbitrary file download. "For security reasons, JavaScript does not allow the remote downloading of files," LAB52 said. "This is why the attackers use the Chrome DevTools Protocol (CDP), an internal protocol of Chromium‑based browsers that can only be used when the –remote-debugging-port parameter is enabled." It's believed that the backdoor is still in the initial stages of development. An early variant of the malware detected in the wild on January 28, 2026, has been observed just communicating with the domain "gnome[.]com" instead of downloading the primary payload from Pastefy. "One of the most notable aspects is the use of the browser to deploy a backdoor, which suggests that the attackers are exploring new ways to evade detection," the Spanish security vendor said. "The browser is advantageous for this type of activity because it is a common and generally non‑suspicious process, it offers extended capabilities accessible through debugging parameters that enable unsafe actions such as downloading remote files, and it provides legitimate access to sensitive resources such as the microphone, camera, or screen recording without triggering immediate alerts."
thehackernews.comMar 16, 2026extracted
APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military
The Russian state-sponsored hacking group tracked as APT28 has been observed using a pair of implants dubbed BEARDSHELL and COVENANT to facilitate long‑term surveillance of Ukrainian military personnel. The two malware families have been put to use since April 2024, ESET said in a new report shared with The Hacker News. APT28, also tracked as Blue Athena, BlueDelta, Fancy Bear, Fighting Ursa, Forest Blizzard (formerly Strontium), FROZENLAKE, Iron Twilight, ITG05, Pawn Storm, Sednit, Sofacy, and TA422, is a nation-state actor affiliated with Unit 26165 of the Russian Federation's military intelligence agency GRU. The threat actor's malware arsenal consists of tools like BEARDSHELL and COVENANT, along with another program codenamed SLIMAGENT that's capable of logging keystrokes, capturing screenshots, and collecting clipboard data. SLIMAGENT was first publicly documented by the Computer Emergency Response Team of Ukraine (CERT-UA) in June 2025. SLIMAGENT, per the Slovakian cybersecurity company, has its roots in XAgent, another implant used by APT28 in the 2010s to facilitate remote control and data exfiltration. This is based on code similarities discovered between SLIMAGENT and previously unknown samples deployed in attacks targeting governmental entities in two European countries as far back as 2018. It's assessed that the 2018 artifacts and the 2024 SLIMAGENT sample originated from XAgent, with ESET's analysis uncovering overlaps in the keylogging between SLIMAGENT and an XAgent sample detected in the wild in late 2014. "SLIMAGENT emits its espionage logs in the HTML format, with the application name, the logged keystrokes, and the window name in blue, red, and green, respectively," ESET said. "The XAgent keylogger also produces HTML logs using the same color scheme." Also deployed in connection with SLIMAGENT is another backdoor referred to as BEARDSHELL that's capable of executing PowerShell commands on compromised hosts. It uses the legitimate cloud storage service Icedrive for command-and-control (C2). A noteworthy aspect of the malware is that it utilizes a distinctive obfuscation technique referred to as opaque predicate, which is also found in XTunnel (aka X-Tunnel), a network traversal and pivoting tool used by APT28 in the 2016 Democratic National Committee (DNC) hack. The tool provides a secure tunnel to an external C2 server. "The shared use of this rare obfuscation technique, combined with its colocation with SLIMAGENT, leads us to assess with high confidence that BEARDSHELL is part of Sednit's custom arsenal," ESET added. A third major piece of the threat actor's toolkit is COVENANT, an open-source .NET post-exploitation framework that has been "heavily" modified to support long-term espionage and to implement a new cloud-based network protocol that abuses the Filen cloud storage service for C2 since July 2025. Previously, APT28's COVENANT variant was said to have used pCloud (in 2023) and Koofr (in 2024-2025). "These adaptations show that Sednit developers acquired deep expertise in Covenant – an implant whose official development ceased in April 2021 and may have been considered unused by defenders," ESET said. "This surprising operational choice appears to have paid off: Sednit has successfully relied on Covenant for several years, particularly against selected targets in Ukraine." This is not the first time the adversarial collective has embraced the dual-implant strategy. In 2021, Trellix revealed that APT28 deployed Graphite, a backdoor that employed OneDrive for C2, and PowerShell Empire in attacks targeting high-ranking government officials overseeing national security policy and individuals in the defense sector in Western Asia.
thehackernews.comMar 10, 2026extracted
APT28 hackers deploy customized variant of Covenant open-source tool
The Russian state-sponsored APT28 threat group is using a custom variant of the open-source Covenant post-exploitation framework for long-term espionage operations. Also tracked as Fancy Bear, Forest Blizzard, Strontium, and Sednit, the APT28 hacker group is known for developing high-end implants and breaching notable entities, such as the German Parliament, multiple French organizations, government networks in Poland, and European NATO member countries. Researchers at cybersecurity company ESET noticed that since April 2024, the Russian group has started using in attacks two implants named BeardShell and Covenant. "This dual-implant approach enabled long-term surveillance of Ukrainian military personnel," ESET notes in a report today. The two pieces of malware have been used recently to target central executive bodies of Ukraine in attacks that exploited the CVE-2026-21509 vulnerability in Microsoft Office via malicious DOC files. The researchers uncovered these malware families after discovering SlimAgent, a keylogging implant deployed in a Ukrainian government system capable of keystroke capture, clipboard collection, and screenshot capture. BeardShell is a modern implant that leverages the legitimate cloud storage service Icedrive for command-and-control (C2) communication. It can execute PowerShell commands in a .NET runtime environment and was used together with SlimAgent, according to a report from CERT-UA in June 2025. ESET found that BeardShell also uses a unique obfuscation technique previously seen in Xtunnel, a network-pivoting tool that APT28 used in the 2010s. In the recent attacks, the Russian threat group paired BeardShell with a heavily modified version of the open-source Covenant .NET post-exploitation framework. The changes they introduced include deterministic implant identifiers tied to host characteristics, modified execution flow to evade behavioral detection, and new cloud-based communication protocols. Since July 2025, the threat actor has used the Filen cloud provider with Covenant. Previously, the attacker used Koofr and pCloud services. ESET says Covenant is used as the primary implant, and BearShell serves as the fallback tool. “Since 2023, Sednit developers have made a number of modifications and experiments with Covenant to establish it as their primary espionage implant, keeping BeardShell mainly as a fallback in case Covenant encounters operational issues, such as the takedown of its cloud-based infrastructure.” - ESET ESET believes that APT28’s advanced malware development team returned to activity in 2024, giving the threat group new long-term espionage capabilities. The technical similarities with 2010-era malware indicate continuity in the threat group’s development team. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 10, 2026extracted
Russian hackers deploy new malware in phishing campaign targeting Ukraine
Russian hackers deploy new malware in phishing campaign targeting Ukraine Researchers have identified a suspected Russian espionage campaign targeting Ukraine that uses two previously undocumented malware strains, according to a new report. The operation begins with a phishing email with a link to a ZIP archive containing a malicious document written in Ukrainian that appears to grant a permit for crossing a Ukrainian border checkpoint, researchers at cybersecurity firm ClearSky said. Opening the archive triggers the download of a malware loader dubbed BadPaw, which then installs a second tool called MeowMeow, a sophisticated backdoor that allows attackers to access infected systems and manipulate files stored locally. According to ClearSky, the backdoor can check whether specific files exist on a device and can read, write or delete data on the compromised machine. Both malware strains include mechanisms designed to evade detection. The MeowMeow backdoor scans infected systems for signs of virtual machines and common cybersecurity analysis tools, automatically terminating itself if it detects a research or sandbox environment. ClearSky attributed the campaign with high confidence to a Russian state-aligned threat actor and with low confidence to the hacking group APT28, also referred to as Fancy Bear, BlueDelta or Forest Blizzard. “The focus on Ukrainian entities, combined with the geopolitical nature of the lure, aligns with Russian strategic objectives,” the researchers said. The phishing emails were sent from addresses hosted by ukr.net, a widely used Ukrainian email service that researchers said has been used in previous campaigns linked to APT28 to harvest credentials and collect intelligence. The report did not identify the targets of the campaign or say whether the attacks were successful. Widely believed to be linked to Russia’s military intelligence agency, APT28 has previously conducted cyber-espionage and credential-harvesting operations against government agencies, defense contractors, weapons suppliers and logistics firms. Earlier this week, Ukraine’s computer emergency response team, CERT-UA, reported a separate hacking campaign targeting Ukrainian government institutions using ShadowSniff and SalatStealer information-stealing malware. The agency attributed the activity to a threat actor tracked as UAC-0252. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaMar 4, 2026extracted
UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware
A Russia-aligned threat actor has been observed targeting a European financial institution as part of a social engineering attack to likely facilitate intelligence gathering or financial theft, signaling a possible expansion of the threat actor's targeting beyond Ukraine and into entities supporting the war-torn nation. The activity, which targeted an unnamed entity involved in regional development and reconstruction initiatives, has been attributed to a cybercrime group tracked as UAC-0050 (aka DaVinci Group). BlueVoyant has designated the name Mercenary Akula to the threat cluster. The attack was observed earlier this month. "The attack spoofed a Ukrainian judicial domain to deliver an email containing a link to a remote access payload," researchers Patrick McHale and Joshua Green said in a report shared with The Hacker News. "The target was a senior legal and policy advisor involved in procurement, a role with privileged insight into institutional operations and financial mechanisms." The starting point is a spear-phishing email that uses legal themes to direct recipients to download an archive file hosted on PixelDrain, a file-sharing service used by the threat actor to bypass reputation-based security controls. The ZIP is responsible for initiating a multi-layered infection chain. Present within the ZIP file is a RAR archive that contains a password-protected 7-Zip file, which includes an executable that masquerades as a PDF document by using the widely abused double extension trick (*.pdf.exe). The execution results in the deployment of an MSI installer for Remote Manipulator System (RMS), a Russian remote desktop software that allows remote control, desktop sharing, and file transfers. "The use of such 'living-off-the-land' tools provides attackers with persistent, stealthy access while often evading traditional antivirus detection," the researchers noted. The use of RMS aligns with prior UAC-0050 modus operandi, with the threat actor known to drop legitimate remote access software like LiteManager and remote access trojans such as RemcosRAT in attacks targeting Ukraine. The Computer Emergency Response Team of Ukraine (CERT-UA) has characterized UAC-0050 as a mercenary group associated with Russian law enforcement agencies that conducts data gathering, financial theft, and information and psychological operations under the Fire Cells branding. "This attack reflects Mercenary Akula's well-established and repetitive attack profile, while also offering a notable development," BlueVoyant said. "First, their targeting has been primarily focused on Ukraine-based entities, especially accountants and financial officers. However, this incident suggests potential probing of Ukraine-supporting institutions in Western Europe." The disclosure comes as Ukraine revealed that Russian cyber attacks aimed at the country's energy infrastructure are increasingly focused on collecting intelligence to guide missile strikes rather than immediately disrupting operations, The Record reported. Cybersecurity company CrowdStrike, in its annual Global Threat Report, said it expects Russia-nexus adversaries to continue conducting aggressive operations with the goal of intelligence gathering from Ukrainian targets and NATO member states. This includes efforts undertaken by APT29 (aka Cozy Bear and Midnight Blizzard) to "systematically" exploit trust, organizational credibility, and platform legitimacy as part of spear-phishing campaigns targeting U.S.-based non-governmental organizations (NGOs) and a U.S.-based legal entity to gain unauthorized access to the victims' Microsoft accounts. "Cozy Bear successfully compromised or impersonated individuals with whom targeted users maintained trusting professional relationships," CrowdStrike said. "Impersonated individuals included employees from international NGO branches and pro-Ukraine organizations." "The adversary heavily invested in substantiating these impersonations, using compromised individuals' legitimate email accounts alongside burner communication channels to reinforce authenticity."
thehackernews.comFeb 24, 2026extracted
2025: The Untold Stories of Check Point Research
Check Point Research (CPR) continuously tracks threats, following the clues that lead to major players and incidents in the threat landscape. Whether it’s high-end financially-motivated campaigns or state-sponsored activity, our focus is to figure out what the threat is, report our findings to the relevant parties, and make sure Check Point customers stay protected. Some of our work naturally makes it into the spotlight through public reports and deep blog posts. However, a large portion of what we uncover remains in the shadows but is used on a day-to-day basis to improve protections, connect the dots between incidents, and keep a watchful eye on known threat actors and infrastructure. In 2025, the activity varied by region and objective. In the Americas, attackers invested in high-value targets, including early ToolShell exploitation assessed as Chinese-nexus activity against North American government organizations. Identity-centric intrusion methods were also prominent, such as AiTM-enabled credential theft in targeted campaigns against researchers within US think tanks. In Europe, the year combined disruption, espionage, influence operations, and financially motivated intrusions. Russian-affiliated activity drove pressure in Eastern Europe and Ukraine, while Chinese and Iranian-nexus actors remained active, and election-related influence efforts persisted, including renewed targeting around Moldova’s parliamentary cycle. Across Asia Pacific and Central Asia, Chinese-nexus espionage was sustained, frequently relying on updated versions of established attack playbooks. In the Middle East and Africa, campaigns reflected a diversified mix of state-aligned operations, destructive activity, and PSOA-linked exploitation, with conflict periods amplifying targeted collection such as attempts to compromise internet-connected cameras. Across these threats, novelty more often came from how familiar techniques were combined than from entirely new tooling. Actors repeatedly used trusted platforms and common enterprise pathways: cloud hosting for command and control, remote administration tooling, DLL side-loading chains, and social engineering patterns such as ClickFix, to reduce detection and improve reliability. Overall, 2025 reinforced the need for durable visibility across identity, cloud, and endpoints, faster closure of exposed and unpatched entry points, and industry collaboration. Check Point Research Untold Stories Timeline – 2025 Key APT campaigns, cyberattacks & threat actor activity tracked throughout the year Jan APT36 Targeting Indian Aerospace Industry RedCurl Weaponized LNK Files Campaign Mar Stealth Falcon Exploits WebDAV 0-day in the Middle East and Africa Apr Samsung Security Release Fixes 0-day Lying Pigeon Campaign Targeting the Moldovan Elections May Flax Typhoon Targets IT Supply Chains in Taiwan GoldenSMTP Targeting Governments in Central Asia Jun Cameras Targeting by Iranian-Nexus Actors Handala Hack Wiper Muddy Water Activity in Israeli Municipality Jul ToolShell Intrusion SilverFox Attacks Web Servers Kimsuky Phishing Campaigns against the US Think Tanks YoroTrooper Targets Eurasian Economic Union Countries Aug Camaro Dragon Targeting Government Sector UAC-0050 Phishing Campaign Zipline Shifting to Europe WIRTE Espionage and Sabotage Sep WhiteLock Ransomware Oct COLDRIVER in Southeast Europe Dec Nimbus Manticore Activity in Africa Figure 1 – Overview of CPR Untold Stories 2025. Americas Throughout the year, the Americas were a focal point for both nation state activity and high-end cybercrime, with a wide mix of actors targeting government and private-sector organizations alike. The state-sponsored groups in particular seem to reserve some of their most innovative tradecraft for targets in the Americas. Whether through zero-day exploitation, abuse of cloud services, or highly refined phishing operations, attackers appear willing to invest more time and sophisticated efforts for targets in this region. ToolShell Exploitation Used as a Zero-day by Chinese-nexus Actors ToolShell is an exploit chain targeting on-premises Microsoft SharePoint and enables unauthenticated remote code execution (RCE) on vulnerable servers. It works by abusing weaknesses in how SharePoint handles certain web service / API requests, which allow attackers to reach code execution without needing valid credentials. ToolShell’s involvement in active exploitation efforts has been observed globally. While analyzing in July the broader wave of ToolShell activity, we found a subset of targeted incidents where the exploit chain appears to have been used as a zero-day, before the original patch was available. In each of these limited early exploitation attempts, the targets were government-sector organizations in North America. We attribute the zero-day exploitation activity to Chinese-nexus threat actors. This assessment is based on the supporting infrastructure we observed in this campaign, which includes router-based relay nodes consistent with Operation Relay Box (ORB)-style networks, an approach most frequently seen in intrusions attributed by multiple vendors to Chinese nexus groups. This assessment aligns with Microsoft Threat Intelligence report that Chinese APTs exploited the vulnerability as a zero-day. Figure 2 – ToolShell Exploitation Timeline. Kimsuky Targeting Think-Tanks in the US Since mid-July, we’ve been tracking a targeted phishing campaign aimed at researchers within US think tanks which focus on North Korean affairs and policy. The campaign relies on spear-phishing emails, often impersonating peers from European universities or NGOs, with invitations to collaborate or participate in academic or policy events. The malicious emails contain either a link or a PDF attachment embedding a QR code, both of which lead to web pages impersonating legitimate organizations. Figure 4 – Example of a phishing landing page (hosted at signup-forms[.]theonlycompany[.]com), explaining the login request. The landing pages claim a login is required and include a button that redirects victims to credential-harvesting sites tailored to their email providers, such as Yahoo, Gmail, or Microsoft. The phishing infrastructure leverages Adversary-in-the-Middle (AiTM) kits to bypass MFA and gain unauthorized access to victims’ email accounts. RedCurl Weaponizes LNK files RedCurl is a sophisticated, Russian-speaking threat actor historically tied to corporate espionage, and most recently, to ransomware operations. The actor has targeted North American entities for years. In more recent activity affecting North America and Asia, we observed a new multi-stage infection chain that pulls a remote resource by abusing the Working Directory parameter in LNK files. The LNKs point to a legitimate Windows binary (such as conhost or rundll32), and pass an argument that references a file located in that remote working directory production[.]dav[.]indeedex[.]workers[.]dev. This combination of living-off-the-land execution, using WebDAV and remote resource loading, appears to contribute to exceptionally low detection rates. While we haven’t observed clear post-exploitation activity in our data, we did see indications suggesting the intrusion path may ultimately lead to the deployment of RedCurl’s custom ransomware. Europe The activity we observed in Europe ranges from operations designed to disrupt, to those intended to influence and mislead, to financially motivated campaigns. Together, these threats threaten every pillar of data security: confidentiality, integrity, and availability. The most aggressive activity is driven by Russian-affiliated actors, especially in Eastern Europe and Ukraine, where they employ a mixture of tactics consistent with aims of espionage, disruption, and “hacktivism.” At the beginning of 2025, we reported on one major espionage campaign, attributed to APT29, which targeted foreign affairs ministries. However, Russia nexus actors isn’t the only major player in this arena: Europe continues to face sustained pressure from Chinese and Iranian nexus threat actors as well, alongside a steady stream of financially-motivated groups targeting the continent. Camaro Dragon Targeting Government Sector In 2025, we tracked multiple Chinese-aligned actors targeting Europe. Within this broader set of operations, we observed a recurring campaign against European government agencies that looks like an evolution of the SmugX activity we reported in 2023. The campaign, likely a subset of Camaro Dragon (also known as Mustang Panda), uses well-crafted phishing to deliver PlugX payloads. The initial infection begins with spear-phishing emails sent from what appear to be government addresses, either compromised mailboxes or spoofed senders, targeting Foreign Affairs ministries across Europe. The messages contain a hyperlink to an HTML landing page hosted on Microsoft Azure’s cloud-based web storage service (*.web.core.windows.net). Figure 5 – Camero Dragon’s Infection Chain. When opened, the HTML executes a short, embedded JavaScript snippet that reconstructs and launches a download link. The script dynamically assembles the next stage URL using ASCII-encoded fragments, then redirects the browser to download an archive file such as 262a1003a2cd04993b29e687686eba573d6202fea8611c437ecbd6312802677a. This archive contains a Windows shortcut (LNK) file that serves as the dropper for the next stage. COLDRIVER in Southeast Europe Despite multiple recent public exposures, the Russian affiliated threat group COLDRIVER (also tracked as UNC4057, Star Blizzard, and Callisto) has not slowed down or paused its activity. Instead, the group continues to rapidly adapt its operations. In Q4 2025, we observed multiple campaigns impersonating US-based nonprofit organizations, including NED (National Endowment for Democracy) and USRF (The US–Russia Foundation), as well as campaigns targeting Southeast Europe that use fake websites impersonating a major regional media and broadcasting company. These campaigns highlight the group’s ability to quickly evolve its tooling and delivery mechanisms in response to exposure. As part of this evolution, COLDRIVER introduced changes to its multi-stage MAYBEROBOT (also known as SIMPLEFIX) malware delivery chain. Beginning with ClickFix-style self-infection, the updated chain incorporates additional stagers with enhanced attacker-side security measures, such as DGA and RSA-based authenticity checks for C2 communications. Figure 6 – ClickFix-style attack staged using a fake United Media website. Lying Pigeon Campaign Targeting the Moldovan Elections In 2024, we exposed Operation MiddleFloor, a campaign in Moldova by the Russian-speaking group Lying Pigeon. Ahead of the October 2024 presidential elections and EU referendum, the group used spoofed emails and forged documents, impersonating EU institutions, Moldovan ministries, and political figures to spread anti-European narratives. We also discovered that previously, Lying Pigeon also targeted other major European political events, including the NATO 2023 summit in Vilnius and Spain’s 2023 general elections. Since mid-April 2025, we observed a new wave of activity aimed at Moldova’s September parliamentary elections. Most of this activity used the same techniques as the MiddleFloor campaign, spreading fake documents to erode trust in Moldovan pro-European leadership. In addition, at the end of May, Lying Pigeon launched a large-scale defamation campaign using over a dozen domains to promote a poster contest attacking PAS, the ruling Party of Action and Solidarity founded by President Maia Sandu. Though framed as citizen-led, it was a coordinated propaganda and disinformation effort running on Lying Pigeon infrastructure. Interestingly, the contest site itself was cloned from a website of a Russian anti-terrorism poster competition held in 2024. In August, a phishing campaign targeting multiple organizations in Ukraine was launched from compromised email accounts. The emails masquerade as communications from the Ukrainian tax authorities and contain a malicious link to the 4sync.com file sharing service, prompting recipients to download a malicious archive named tax_gov_ua_zapit_15_08_2025_X.zip. Upon successful execution, a Remote IT support tool is installed on background, granting unauthorized access to the threat actor. This campaign shares similarities with UAC-0050. Figure 8 – UAC-0050 Phishing masquerading as tax.gov.ua. Zipline Shifting to Europe Earlier this year, we reported a sophisticated phishing campaign targeting US organizations with unusually elaborate social engineering. The campaign, named ZipLine, was noteworthy because the attacker reached out through the victim’s public “Contact Us” form, reversing the typical phishing flow and prompting the organization to initiate the email exchange. Since that publication, we’ve seen a noticeable shift in both the group’s TTPs and its targeting, with a clear refocus on Europe. Recent waves lean heavily on HR-themed lures, and our data suggests the actor is running country-by-country campaigns, most notably against the UK, Poland, Italy, and the Czech Republic. The tooling also appears to have evolved into newer iterations of MixShell, with the actor now relying almost entirely on herokuapp domains for C2 communication. Figure 9 – Zipline lure targets Europe. Asia Pacific and Central Asia The activity we observed across Asia reflects a sustained regional espionage push by Chinese-aligned actors. For much of the year, the dominant TTPs (Tactics, Techniques, and Procedures) we saw were best described as updated versions of familiar playbooks: reusing modular backdoor ecosystems such as PlugX and ShadowPad, and repeating patterns that were effective for these groups in the past. At the same time, a smaller subset of APT activity stood out for being more deliberate and mature, reflecting a higher investment in tradecraft and operational discipline than the broader baseline we typically see in the region. However, the picture on the ground is still unclear as many of the same environments are targeted by multiple actors over long periods, leaving behind overlapping infrastructure, tooling, and artifacts. This creates an intertwined landscape that can be difficult to untangle, especially in Southeast Asia. GoldenSMTP Targeting Governments in Central Asia Throughout 2025, we observed multiple instances of activity that we determined to be an evolution of the IndigoZebra APT. These events primarily target Central Asia and rely on a mix of backdoors and supporting tools. Initial access is typically delivered via password-protected ZIP archives using phishing-style filenames, followed by DLL hijacking to install the first backdoor. Across the intrusion chain, we also saw a broader toolkit that included Pandora RC installer (open-source IT remote control software), shellcode loaders, and the NPPSPY credential stealer. Figure 10 – GoldenSMTP masquerades as SentinelOne Agent using debug strings. Next, the attackers deploy a dedicated SMTP/IMAP-based implant, named GoldenSMTP, which communicates through attacker-controlled email accounts, often named after local athletes, inside the target organization. This unusual C2 channel, combined with the use of compromised systems, appears to be at least partly responsible for the notably low detection rates of the backdoors installed in the later stages of the intrusion. Several of the samples showed code overlaps with older IndigoZebra malware, and the operation itself reflects familiar patterns: targeting Central Asia, reusing older infrastructure, relatively simple obfuscation, and checks for Russian-language systems. Flax Typhoon Targets IT Supply Chains in Taiwan We observed an intrusion set at a Taiwan-based cloud service provider where the threat actor abused legitimate security products to execute a DLL side-loading chain. The side-loaded DLL acted as a PlugX loader, which then brought in multiple plugins and injected them into other processes, with capabilities such as reverse shell access and keylogging. In this case, the built-in nslookup.exe utility was used to initiate C2 communication. After establishing a foothold, the attackers scanned the network and moved laterally using RDP. We also identified a SoftEther VPN binary placed at C:\Windows\SysWOW64\conhost.exe, a technique that other security vendors linked to the APT group known as Flax Typhoon. Flax Typhoon has been flagged by US government agencies as a major cyber risk for the technology ecosystem, including managed service providers (MSPs) and other IT service providers. SilverFox Attacks Web Servers The SilverFox APT group continues to target organizations across East Asia, with a particular focus on Taiwan and Japan, using a multi-stage backdoor known publicly as ValleyRAT. As part of the infection chain, the group employs a “bring your own vulnerable driver” (BYOVD) technique to terminate security product processes and reduce the chances of detection. We also identified a newly observed initial access vector: compromised PHP servers exposed to remote code execution. After successful exploitation, the group leverages the legitimate Windows msiexec component to install a ValleyRAT implant from hxxp[:]//aadcasc[.]cn-nb1[.]rains3[.]com/100ww.msi. Figure 11 – ValleyRAT web exploitation chain. YoroTrooper Targets Eurasian Economic Union Countries Throughout 2025, YoroTrooper, a threat group active in CIS countries since at least 2020, was observed targeting member states of the Eurasian Economic Union (EAEU) countries and its regulatory body, the Eurasian Economic Commission. Targets included government and diplomatic entities, as well as infrastructure projects in these countries. The attackers used PDF documents to lure victims to either phishing pages that steal credentials or to cloud-based file sharing services hosting malware. Consistent with other YoroTrooper campaigns, the threat actors deployed “burner” RATs as payloads, typically leveraging services such as Telegram and Discord for C2 communications. Figure 12- Example of phishing PDF document (549df969dc5b340b4fc850584a01c767ca8a1bd712f16210f164f85e26c3e58b) targeting government entity in Kyrgyz Republic. APT36 Targeting Indian Aerospace Industry At the beginning of 2025, we identified a targeted phishing campaign aimed at government entities and the Indian aerospace industry. Based on infrastructure overlap, targeting focus, and operational tradecraft, we can attribute the activity with moderate confidence to APT36. Phishing emails, with the subject line “RFI for Surveillance Systems for [REDACTED] State Police,” were sent from a compromised legitimate local Indian government email account, lending significant credibility to the lure. The campaign leveraged ISO attachments containing malicious LNK files, which executed embedded batch scripts. These scripts deployed a stealer malware capable of exfiltrating documents and other sensitive files from compromised hosts, and shares code similarity with ObliqueRAT. Later in the year, we observed additional activity consistent with this campaign targeting entities in Afghanistan, indicating an expansion of the threat group’s operational scope. Figure 13 – Snippet of PDF lure targeting the Indian aerospace industry. Middle East and Africa Recent activity across the Middle Eastern and North African (MENA) region reflects a diversified threat landscape with state-aligned advanced persistent threat (APT) groups, private sector offensive actors (PSOAs), and destructive operators deploying wipers. Campaigns blend legacy social engineering with increasingly disciplined operational planning, and use legitimate cloud apps, and code-signing or supply chain-style trust signals to lower detection rates. Private Sector Offensive Actors Some of the more distinctive activity we’ve been tracking is commonly associated with what are known as Private Sector Offensive Actors (PSOA). Many of the PSOA-linked clusters we observed this year were active in the Middle East, where this type of innovative capability continues to surface. One of our prominent findings was the discovery of a zero-day exploited by StealthFalcon: CVE-2025-33053, a vulnerability used to target high-profile organizations in Turkey, Qatar, Egypt, Ethiopia and Yemen. StealthFalcon, however, is not unique. Throughout 2025, we identified additional activity clusters that stood out in terms of their behavior and tradecraft. We came across one of them while tracking high-profile sample submitters in the Middle East. The activity consisted of a cluster of suspicious TIFF (an image file format for storing raster graphic images) files that contained embedded ELF payloads aimed at Android devices. Our analysis indicated the files were exploiting a vulnerability, later disclosed as CVE-2025-21042, in the way Samsung parses TIFF/DNG files. Based on the tradecraft, infrastructure overlaps, and recurring keywords like “Bridge Head,” we assess the operator to be a private sector offensive actor. Additional research into the same activity, called LANDFALL, reached similar conclusions. We saw indications the campaign affected targets in Iraq, Iran, Turkey, Bahrain, Morocco and Pakistan. Iranian Activity Israeli-Iranian War: Targeting Cameras During the twelve-day Israeli–Iranian war in June, threat actors largely stuck to their familiar playbooks, primarily using spear phishing campaigns to deploy wipers and backdoors. One standout trend we observed was a sharp increase in attempts to compromise specific Israeli cameras by exploiting CVE-2023-6895 and CVE-2017-7921 via infrastructure we associate with Iranian actors. In several major conflicts in recent years, compromising internet-connected cameras proved to be an effective way to support bombing damage assessment (BDA) by providing near–real-time visibility into strike impacts. This wave targeting Israeli cameras appears to fit that pattern and aligns with prior public disclosures by Israeli officials that Iran-nexus actors seek access to private CCTV feeds to assess the accuracy of their missile strikes and refine subsequent targeting efforts. Figure 14 – Spike in cameras targeting in Israel. MuddyWater Password Spray in Israeli Municipality In late June, a successful password spray activity originating from a Nord VPN infrastructure affected a municipal government in Israel. One month later, we observed a successful login attempt from the same attacker infrastructure to an email account which then sent spear phishing emails to recipients in Israel. The phishing email contained an embedded link, hxxps[:]//pharmacynod[.]com/join/join.html, used as a decoy invitation to join a Teams conversation. The landing page is a ClickFix page that tricks the user into pasting a PowerShell script into the Run dialog and executing it. This script is a RAT which initially collects information about the infected machine and can execute arbitrary PowerShell commands received from the command and control server. This script’s obfuscation method aligns with previous PowerShell backdoors associated with MuddyWater. Figure 15 – MuddyWater ClickFix Teams lure. Nimbus Manticore Activity in Africa We recently uncovered a long-running campaign that we attribute to Nimbus Manticore, an IRGC-affiliated actor active across the region and parts of Europe. What we observed highlights this actor’s evolution: while continuing to lean on familiar phishing themes, the actor has also begun deploying more sophisticated malware, making himself something of an outlier compared to much of the broader Iranian threat landscape. As we continue to track this operation, we’ve observed renewed activity targeting Northeast Africa, impersonating T-Mobile with a fake hiring website careerst-mobile[.]com and using similar tradecraft which suggests the campaign remains active and adaptable. Figure 16 – Renewed Nimbus Manticore phishing activity targeting Africa with impersonated T-Mobile site. Iran-Nexus Wipers Throughout the year, multiple Iran-aligned actors targeted Israel with disruptive campaigns involving wipers and ransomware. These operations, often at least partly opportunistic, are designed to interfere with the day-to-day functioning of Israeli organizations. Among the most prominent groups behind this activity are Void Manticore (Handala Hack) and Cotton Sandstorm, carrying out attacks using ‘WhiteLock’ ransomware, deployed after WezRat infostealer. Figure 17 – ‘WhiteLock’ ransomware chat server. One such campaign, likely conducted by Handala, involved a phishing email sent to hundreds of organizations across Israel. The messages were delivered from a compromised account belonging to an Israeli CRM solution provider. Recipients were instructed to “back up” their files by downloading a malicious .msi installer (6eb7dbf27a25639c7f11c05fd88ea2a301e0ca93d3c3bdee1eb5917fc60a56ff) hosted on Mega file share. When executed, the installer deployed a wiper that iterates over user file folders and overwrites files with spaces. In parallel, a malicious PowerShell script changed the user’s desktop wallpaper to display a political message tied to the Israeli-Hamas war. WIRTE: Espionage and Sabotage At the end of 2024, we published research connecting a wave of destructive activity in Israel, known as ‘Cyber Toufan Al-Aqsa’, to WIRTE, a Hamas-associated threat actor. In 2025, the group continued its destructive operations with new variants of SameCoin wiper, while also running parallel campaigns aimed at Arabic-speaking political entities across the Middle East, with a particular focus on Jordan and Egypt. In these campaigns, targets are lured into downloading a malicious archive (1f3bd755de24e00af2dba61f938637d1cc0fbfd6166dba014e665033ad4445c0) from a Dropbox URL. After the archive is extracted, the victim is presented with a benign Microsoft binary and a decoy file bearing an Arabic-language filename, which the user is prompted to open. That execution triggers DLL side-loading, pulling in a malicious DLL that serves as a loader. It also exfiltrates Base64‑encoded host information to a remote C2 server, and downloads and executes an additional payload, most commonly Havoc. In recent activity, the attacker used DigitalOcean-hosted infrastructure for C2 instead of the Cloudflare-backed setup that featured in previous longer-running operations. Figure 18 – Wirte Arabic-language lure. Conclusion Looking back at 2025, the threat landscape became more crowded, messy, and increasingly interconnected. Across different regions, we saw state-backed groups, private offensive actors, and high-end cybercrime operating side by side, sometimes even within the same networks. Zero-days, cloud-focused intrusions, and well-crafted phishing are no longer just rare outliers; we observed them repeatedly in multiple attacks as practical, reliable ways to get results. At the same time, many of the campaigns we uncovered show that novelty often lies less in entirely new tooling and more in how familiar techniques are combined and deployed. Actors reused infrastructure, malware frameworks, and social engineering themes, but adapted them to new targets, regions, and operational goals. In several cases, incomplete or internal-only research threads offered insight into how attackers test ideas, quietly iterate, and refine their approach over time. Ultimately, these observations reinforce the need for sustained visibility, collaboration, and context-driven research. Threat actors continue to invest where impact matters most, while opportunistic campaigns exploit gaps that are overlooked or left unpatched. By sharing these stories, both the well-known and the previously untold, we hope to contribute to a clearer picture of attackers’ behavior and help strengthen collaboration between security researchers and vendors moving forward. “The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign Check Point Research Publications August 11, 2017 “The Next WannaCry” Vulnerability is Here Check Point Research Publications March 12, 2026 “Handala Hack” – Unveiling Group’s Modus Operandi SUBSCRIBE TO CYBER INTELLIGENCE REPORTS We value your privacy! BFSI uses cookies on this site. We use cookies to enable faster and easier experience for you. By continuing to visit this website you agree to our use of cookies.
research.checkpoint.comFeb 23, 2026extracted
Phishing attempt against Reporters Without Borders attributed to Russia-linked group
Phishing attempt against Reporters Without Borders attributed to Russia-linked group A Russia-aligned threat actor attempted to compromise the nonprofit Reporters Without Borders (RSF) in a recent phishing campaign, according to new research. The hacking group — also known as Callisto, ColdRiver or Star Blizzard and previously linked by Western governments to Russia’s FSB security service — has been active since at least 2017 and is known for credential-harvesting operations against NGOs, government bodies and organizations supporting Ukraine. According to cybersecurity firm Sekoia, one of RSF’s core members received a phishing email in March from a ProtonMail account impersonating a trusted contact. The message — written in French and using the correct email signature — asked the recipient to review a document but did not include an attachment, a tactic Callisto has used before to prompt targets to request a follow-up file. When the RSF member asked for the missing document, the attacker replied in English with a link hosted on a compromised website. The link was designed to redirect the victim to a malicious PDF, but the file could not be retrieved after ProtonMail blocked the operator’s account, Sekoia said. RSF, which provides support to reporters under threat and has helped Russian journalists flee the country, was labeled an “undesirable organization” by the Kremlin in August 2025 — a designation that effectively criminalizes its activity in Russia. The organization has not publicly commented on the attempted intrusion or the hackers’ suspected motives. Sekoia said another organization, which the researchers did not name, was targeted with a similar lure. In that case, the victim received a decoy PDF claiming the file was encrypted and instructing the user to open it via ProtonDrive. Clicking the link redirected the target to a phishing kit designed to harvest ProtonMail credentials. The kit presented victims with a spoofed ProtonMail login page where the email address was pre-filled. Injected JavaScript forced the cursor to remain in the password field — a trick meant to increase the likelihood the target would enter their credentials. Callisto is known for espionage campaigns against Western governments, defense contractors, research institutions and NGOs, with a particular focus on Eastern Europe and countries supporting Ukraine. Previous targets include NATO-linked organizations, a Ukrainian defense company and individuals with expertise on Russia. Last September, for example, the U.S.-based Free Russia Foundation said it was investigating a breach after thousands of internal emails and documents — including grant reports and correspondence — were leaked online. The organization believes the intrusion was linked to Callisto, saying attackers compromised “a number of entities” to steal the data. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaDec 4, 2025extracted
French NGO Reporters Without Borders Targeted by Star Blizzard
A fresh wave of spear-phishing activity linked to the Russia-nexus intrusion set Star Blizzard, also known as ColdRiver or Calisto, has been identified by cybersecurity researchers. The group has been active since 2017 and is attributed by several Western governments to Russia's FSB Center 18. According to a new analysis by Sekoia.io's TDR team, the latest incidents were reported in May and June 2025 by two organizations, including Reporters Without Borders (RSF), prompting a closer look at how the operators refined their credential-harvesting techniques. A Familiar Intrusion Set Expands Its Focus The new series of phishing attempts follows Star Blizzard's long-running focus on Western entities backing Ukraine. The group is known for impersonating trusted contacts and prompting targets to request missing or malfunctioning attachments. Once the victim requests the file, the attacker sends a second message containing a link to malware or a phishing page. In one case involving RSF in March 2025, a ProtonMail address mimicking a legitimate contact sent a French-language email asking a core member to review a document. No file was attached. When the member requested it, the operators replied in English with a link routed through a compromised website to a ProtonDrive URL. However, the file itself could not be retrieved because ProtonMail had blocked the associated account. A second victim received a file labeled as a PDF that was actually a ZIP archive disguised with a .pdf extension. The final stage of the attack used a typical Calisto decoy PDF that claimed to be encrypted and instructed the user to open it in ProtonDrive. The link again sent the target through a redirector hosted on a compromised website. Infrastructure Points to Ongoing Activity The phishing kit analyzed by TDR, located on account.simpleasip[.]org, appeared to be custom built. It targeted ProtonMail accounts using an Adversary-in-the-Middle (AiTM) setup that relays two-factor authentication (2FA). Analysts found injected JavaScript designed to keep the cursor locked to the password field and to interact with an attacker-controlled API for handling CAPTCHA and 2FA prompts. Key observations included: Modified ProtonMail interface elements Persistent password-field focus API-based credential processing Star Blizzard's infrastructure included servers hosting phishing pages and others serving as API endpoints. Many domains were tied to Namecheap services, while some earlier ones were registered via Regway to help analysts track the cluster over time. "Despite numerous publications on this threat actor, Calisto continues its spear-phishing campaigns for credential harvesting or code execution via the ClickFix technique," Sekoia warned. "We are at the disposal of any NGO wishing to analyse and/or attribute attack campaigns to a cluster of activity."
infosecurity-magazine.comDec 3, 2025extracted
Russian suspect detained in Thailand is allegedly tied to Void Blizzard group
Russian suspect detained in Thailand is allegedly tied to Void Blizzard group A suspected Russian hacker arrested in Thailand earlier this month is reportedly linked to a relatively new Kremlin-aligned threat actor that has targeted government and critical infrastructure networks across Europe and North America, according to media reports. Thai police last week confirmed the detention of a “world-famous hacker” wanted by the United States for cyberattacks on government agencies. Russian state-controlled outlet RT later identified the suspect as 35-year-old Denis Obrezko, a Stavropol native who previously worked for major Russian IT firms “developing high-tech systems for domestic industries.” Obrezko was detained on November 6 in a joint operation involving the FBI and Thai police, according to local media reports citing law enforcement. Officers raided his hotel room on the resort island of Phuket just a week after he arrived in the country. They seized laptops, mobile phones and digital wallets. According to reports last week, the suspect was being held in Bangkok following his arrest, pending extradition to the United States. His family has acknowledged the arrest and said they are seeking legal representation in an effort to block his transfer to American authorities, according to RT. Russia’s embassy in Bangkok has also demanded consular access. Thai officials have not publicly named the suspect, but local police sources told CNN that Obrezko is allegedly a member of Void Blizzard, also known as Laundry Bear — a Russia-affiliated threat actor first detailed by Microsoft earlier this year. A newer Blizzard In a May report, Microsoft described Void Blizzard as a relatively new espionage advanced persistent threat (APT) group operating in support of Russian government interests. (The company labels Russia-linked groups with “Blizzard.”) The hackers have targeted organizations across government, defense, transportation, media, NGOs and healthcare, with a particular focus on Europe and North America. According to Microsoft, Void Blizzard typically uses purchased or stolen credentials to infiltrate networks and exfiltrate large volumes of emails and internal documents. In September 2024, Dutch intelligence services said Void Blizzard had breached several Dutch organizations, including the national police, and stolen “work-related contact information.” “The threat actor’s prolific activity against networks in critical sectors poses a heightened risk to NATO member states and allies to Ukraine in general,” Microsoft said. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaNov 18, 2025extracted
Russian Hacking Group Sandworm Deploys New Wiper Malware in Ukraine
The Russian-backed hacking group Sandworm deployed data wiper malware in Ukraine in the second and third quarter of 2025, according to ESET. In its APT Activity Report Q2 2025–Q3 2025, the Slovakia-based cybersecurity company provided an overview of the activity of advanced persistent threat (APT) groups across the world from April to September 2025. The report, published on November 6, revealed that Sandworm deployed data wipers, including Zerolot and Sting against organizations in Ukraine. Targets ranged from governmental entities, companies in the energy and logistics industries and the grain sector. Sandworm, also known as APT44, Telebots, Voodoo Bear, Iridium, Seashell Blizzard and Iron Viking, has been associated to Russia's military intelligence service’s (GRU) unit MUN 74455 by several cybersecurity companies and government agencies. ESET assessed that the group’s likely objective for deploying new wipers was to weaken the Ukrainian economy. Russian Groups Use Spear Phishing and Backdoor For Cyber Espionage The ESET report noted that other Russian-aligned APT groups also maintained their focus on Ukraine and countries with strategic ties to Ukraine, while also expanding their operations to European entities. While Sandworm’s objective seemed to be to disrupt Ukrainian organizations, other Russian nation-state groups pursued cyber espionage goals through a combination of spear phishing campaigns and backdoor implants. Gamaredon remained the most active APT group targeting Ukraine, with a noticeable increase in intensity and frequency of its operations during the reported period. “This surge in activity coincided with a rare instance of cooperation between Russia-aligned APT groups, as Gamaredon selectively deployed one of Turla’s backdoors. Gamaredon’s toolset, possibly also spurred by the collaboration, continued to evolve, for example, through the incorporation of new file stealers or tunneling services,” the ESET researchers wrote. Notably, ESET reported that another Russia-aligned threat actor, InedibleOchotense, conducted a spear phishing campaign impersonating the cybersecurity company. “This campaign involved emails and Signal messages delivering a trojanized ESET installer that leads to the download of a legitimate ESET product along with the Kalambur backdoor,” the report read. Some Russian groups expanded their targeting beyond Ukraine. For instance, RomCom, another of the most active Russian APT groups, exploited a zero-day vulnerability in WinRAR to deploy malicious DLLs and deliver a variety of backdoors, with a focus on the financial, manufacturing, defense and logistics sectors in the EU and Canada. Overview of Global APT Activity The ESET report also highlighted China-aligned APTs continued focus on geopolitical espionage, targeting Latin America (FamousSparrow), Southeast Asia, the Us US and Europe (Mustang Panda), Taiwan’s healthcare (Flax Typhoon) and Central Asia’s energy sector (Speccom). Meanwhile, Iran-aligned hacking group MuddyWater escalated its internal spear phishing tactics – sending malicious targeted emails from compromised inboxes within the target organization – while BladedFeline updated infrastructure and GalaxyGato deployed an upgraded backdoor and DLL-hijacking credential theft. Finally, some North Korea-aligned APTs expanded their cryptocurrency heists and espionage tactics to Uzbekistan, while several groups from the same country – DeceptiveDevelopment, Lazarus, Kimsuky and Konni – were observed targeting South Korean diplomats and academics for revenue and geopolitical gains.
infosecurity-magazine.comNov 7, 2025extracted
Destructive Russian Cyberattacks on Ukraine Expand to Grain Sector
Russian state-sponsored groups continue their cyber assaults on Ukraine and are now aiming their destructive wipers at more industries, including the grain sector, ESET’s latest APT activity report shows. Over the past months, activity associated with Russian APTs focused on European Union member states and Ukraine, typically relying on spear-phishing emails as the initial access vector. According to ESET, even the non-Ukrainian targets appear linked to the country and the overall war efforts, suggesting that Russian intelligence is mobilizing attention and resources to the ongoing conflict. In this context, recent destructive cyberattacks attributed to Sandworm (also known as APT44, Iridium, Seashell Blizzard, TeleBots, and Voodoo Bear, and associated with GRU) stand out. In April, Sandworm targeted a Ukrainian university with the Zerolot and Sting wipers. In June and September, the APT was seen deploying multiple data-wiping malware variants against Ukrainian governmental, energy, logistics, and grain entities. The not-so-common targeting of the grain sector, which remains the main source of revenue for the country, suggests an attempt to weaken Ukraine’s war economy, ESET notes in its report (PDF). The cybersecurity firm also observed a collaboration between the APT and UAC-0099, a Russian threat actor conducting initial intrusions and then transferring targets of interest to Sandworm. “These destructive attacks by Sandworm are a reminder that wipers very much remain a frequent tool of Russia-aligned threat actors in Ukraine. Although there have been reports suggesting an apparent refocusing on espionage activities by such groups in late 2024, we have seen Sandworm conducting wiper attacks against Ukrainian entities on a regular basis since the start of 2025,” ESET notes. Gamaredon, which was seen working with Turla in recent attacks, continued to refine its main stealers, dubbed PteroPSDoor and PteroVDoor, and has adopted new tunneling and serverless computing services. In May, a threat actor tracked as InedibleOchotense was seen impersonating ESET in attacks against various Ukrainian entities, via spear-phishing emails and Signal text messages. Another Russian APT that stood out this year is RomCom (also tracked as Storm-0978, Tropical Scorpius, and UNC2596), which exploited a zero-day vulnerability in WinRAR to deploy various backdoors against defense, financial, logistics, and manufacturing entities in Europe and Canada. “Gamaredon remained the most active APT group targeting Ukraine, with a noticeable increase in the intensity and frequency of its operations. Similarly, Sandworm focused on Ukraine — albeit with destruction as its motive rather than Gamaredon’s cyberespionage,” ESET notes. The cybersecurity firm’s APT activity report also details the latest attacks associated with Chinese, Iranian, and North Korean threat actors. Related: Former US Defense Contractor Executive Admits to Selling Exploits to Russia Related: Russian Government Now Actively Managing Cybercrime Groups: Security Firm Related: Russian APT Switches to New Backdoor After Malware Exposed by Researchers Related: Microsoft: Russia, China Increasingly Using AI to Escalate Cyberattacks on the US
securityweek.comNov 7, 2025extracted
Russian APT Switches to New Backdoor After Malware Exposed by Researchers
The Russian state-sponsored APT known as Star Blizzard has been using a new backdoor in attacks after its LostKeys malware was detailed in a public report in June, Google says. Also tracked as Callisto, ColdRiver, Seaborgium, and UNC4057, Star Blizzard has been active since at least 2019, and has been publicly linked to Russia’s Federal Security Service (FSB) by the US in December 2023. In a June report, Google detailed how the APT was using the ClickFix technique to deliver the LostKeys malware as part of a multi-stage infection chain that also involved the use of a first-stage PowerShell script. Within days of the report, Star Blizzard started using new malware families in attacks and never deployed LostKeys again, Google now says. The APT also dropped the PowerShell infection chain, opting instead to rely on the victim’s execution of a malicious DLL via rundll32. Initially analyzed by Zscaler in September, the recent Star Blizzard attacks continue to rely on ClickFix for infection: victims are lured to pages masquerading as information resources for members of civil society and think tanks in Russia and convinced to execute malicious commands in the Windows Run box. The commands result in a malicious DLL being downloaded on the victim’s system. Dubbed NoRobot by Google (and BaitSwitch by Zscaler), the DLL has been designed to retrieve the next-stage payload and achieve persistence. Earlier versions of NoRobot, Google says, were fetching a Python backdoor dubbed YesRobot, which had limited functionality and made typical backdoor functionality cumbersome to implement. Thus, the APT abandoned YesRobot in favor of a new backdoor, MaybeRobot (tracked as SimpleFix by Zscaler), also deployed via NoRobot. Deployed as a heavily obfuscated PowerShell script, the malware has support for three commands provided by its operator. Based on these, it can execute files, commands, and PowerShell blocks. Likely built to replace YesRobot, and offering increased flexibility in performing activities on the infected systems, MaybeRobot has minimal built-in functionality and still requires an operator for more complex operations. Between May and September 2025, Star Blizzard made multiple changes to NoRobot, mainly focused on evading detection, and updated its infection chain as it transitioned to deploying MaybeRobot as the final stage. “Over the course of this period of time, Coldriver simplified their malware infection chain and implemented basic evasion techniques, such as rotating infrastructure and file naming conventions, paths where files were retrieved from, how those paths were constructed, changing the export name and changing the DLL name,” Google explains. Related: Microsoft: Russia, China Increasingly Using AI to Escalate Cyberattacks on the US Related: Dutch Teens Arrested for Allegedly Helping Russian Hackers Related: US Offers $10 Million for Three Russian Energy Firm Hackers Related: Amazon Disrupts Russian Hacking Campaign Targeting Microsoft Users
securityweek.comOct 22, 2025extracted
Russian hackers evolve malware pushed in "I am not a robot" captchas
The Russian state-backed Star Blizzard hacker group has ramped up operations with new, constantly evolving malware families (NoRobot, MaybeRobot) deployed in complex delivery chains that start with ClickFix social engineering attacks. Also known as ColdRiver, UNC4057, and Callisto, the Star Blizzard threat group abandoned the LostKeys malware less than a week after researchers published their analysis and leveraged the *Robot malicious tools "more aggressively" than in any of its previous campaigns. In a report in May, the Google Threat Intelligence Group (GTIG) said that it observed the LostKeys malware being leveraged in attacks on Western governments, journalists, think tanks, and non-governmental organizations. The malware was used for espionage purposes, its capabilities including data exfiltration based on a hardcoded list of extensions and directories. After publicly disclosing the LostKeys malware, GTIG researchers say that ColdRiver completely abandoned it and started to deploy new malicious tools, tracked as NOROBOT, YESROBOT, and MAYBEROBOT, in operations just five days later. According to GTIG, the retooling started with NOROBOT, a malicious DLL delivered through “ClickFix” attacks involving fake CAPTCHA pages that tricked the target into executing it via rundll32 under the guise of a verification process. The hackers try to trick the target into performing an "I am not a robot" a captcha challenge to prove they are human by executing a command that launches the NOROBOt malware. Researchers at cloud security company Zscaler analyzed NOROBOT in September and named it BAITSWITCH, along with its payload, a backdoor they called SIMPLEFIX. Google says that NOROBOT has been under constant development from May through September. NOROBOT gains persistence through registry modifications and scheduled tasks, and initially retrieved a full Python 3.8 installation for Windows in preparation for the YESROBOT Python-based backdoor. However, GTIG notes that YESROBOT's use was short-lived, likely because the Python installation was an obvious artifact that would draw attention, as ColdRiver abandoned it for another backdoor, a PowerShell script called MAYBEROBOT (identified as SIMPLEFIX by Zscaler). Since early June, a "drastically simplified" version of NOROBOT started to deliver MAYBEROBOT, which supports three commands: download and execute payloads from a specified URL execute commands through the command prompt execute arbitrary PowerShell blocks After execution, MAYBEROBOT returns the results to distinct command-and-control (C2) paths, giving Coldriver feedback on operational success. Google’s analysts comment that MAYBEROBOT’s development appears to have stabilized, with the threat actors now focusing more on refining NOROBOT to be stealthier and more effective. The researchers noticed a shift from complex to simpler and then again to a complex delivery chain that splits cryptographic keys across multiple components. Decrypting the final payload depended on combining the pieces correctly, the researchers say. "This was likely done to make it more difficult to reconstruct the infection chain because if one of the downloaded components was missing the final payload would not decrypt properly," GTIG notes in the report. ColdRiver attacks delivering NOROBOT and the subsequent payloads to targets of interest have been observed in attacks between June and September. ColdRiver operations have been attributed to the Russian intelligence service (FSB). The group has been engaged in cyber-espionage activities since at least 2017. Despite efforts to obstruct its operations through infrastructure disruptions [1, 2], sanctions, and exposing its tactics, ColdRiver remains an active and evolving threat. Typically, the threat group deploys malware in phishing attacks, and researchers have yet to find the reason for the hackers' moving to ClickFix attacks. One explanation could be that ColdRiver now uses the NOROBOT and MAYBEROBOT malware families on targets previously compromised through phishing and have already stolen emails and contacts. Re-targeting them may be " to acquire additional intelligence value from information on their devices directly," the researchers surmise Google’s report lists indicators of compromise (IoCs) and YARA rules to help defenders detect Robot malware attacks. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comOct 21, 2025extracted
Russian Coldriver Hackers Deploy New 'NoRobot' Malware
The Russian-affiliated hacking group Coldriver has been observed deploying a new malware set, according to researchers at the Google Threat Intelligence Group (GTIG). This malware set, made of several families connected via a delivery chain, seems to have replaced Coldriver’s previous primary malware LostKeys since it was publicly disclosed in May 2025, said a GTIG report published on October 20. The researchers noted that the new set was used more aggressively than any other previous malware campaigns ever attributed to the group. This indicates a rapidly increased development and operations tempo from Coldriver, according to GTIG. Coldriver’s Previous Campaigns Coldriver, also known as Star Blizzard, Callisto and UNC4057, is a threat group with attributed links to Russia’s intelligence service, the FSB. Active since at least 2017, the group is known to focus on credential phishing campaigns targeting high-profile NGOs, former intelligence and military officers and NATO governments for espionage purposes. In December 2023, the UK’s National Cyber Security Centre (NCSC) said the group was behind a sustained cyber campaign aimed at interfering in UK politics and democratic processes. In January 2024, Google observed the group going beyond phishing for credentials to delivering malware capable of exfiltrating sensitive information from the target. In May 2025, GTIG detected that Coldriver had used a new malware strain, called LostKeys, in malicious campaigns between January and March of the same year. This new strain has not been observed since the publication of the disclosure, GTIG said in its new October 20 report. Inside Coldriver’s NoRobot, YesRobot and MaybeRobot Instead, Coldriver seemed to have shifted to a new set of malware families tracked by Google as NoRobot, YesRobot and MaybeRobot. The attack starts with a ‘ClickFix-style’ phishing lure, a fake CAPTCHA page designed to trick the victim into thinking they must verify they’re "not a robot." This lure is tracked by Google as ColdCopy. The page prompts the user to download and run a malicious dynamic-link library (DLL) – tracked as NoRobot – via rundll32.exe, a legitimate Windows tool. The DLL’s export function (humanCheck) is named to reinforce the CAPTCHA deception. This replaces older methods that relied on PowerShell, making it harder for security tools that monitor script-based execution to detect the attack. Once executed, the NoRobot DLL acts as a downloader. Early versions used a split-key cryptography scheme, with parts of the decryption key hidden in downloaded files and the Windows Registry (e.g. under HKEY_CURRENT_USER\SOFTWARE\Classes\.pietas). This makes analysis more difficult because missing any component would break the decryption. NoRobot then fetches a self-extracting Python 3.8 installer, two encrypted Python scripts (libsystemhealthcheck.py and libcryptopydatasize.py) from a malicious domain (inspectguarantee[.]org) and a scheduled task to ensure the malware survived reboots. The Python scripts are combined to decrypt and launch a minimal Python-based first-stage backdoor that communicates with a hardcoded command-and-control (C2) server over HTTPS, tracked as YesRobot. GTIG noted that Coldriver abandoned YesRobot after just two weeks, likely because it was too cumbersome and easy to detect – notably because of the Python installation. The researchers suggested that YesRobot served as a temporary stopgap after the group’s previous malware, LostKeys, was exposed. Around June 2025, Coldriver switched to MaybeRobot, a more flexible PowerShell-based backdoor, with no Python script needed. In this new version, NoRobot was simplified to fetch a single logon script that persisted MaybeRobot via a PowerShell command added to the user’s login script. MaybeRobot uses a custom C2 protocol with three core commands: Download and execute a file from a URL Run a command via cmd.exe Execute a PowerShell block Unlike YesRobot, MaybeRobot’s design is extensible, meaning operators can send complex commands dynamically, but the backdoor itself still lacks built-in features, such as automatic data exfiltration. Coldriver Alternates Noisy and Stealthy NoRobot Infection Chains Between June and September 2025, Coldriver evolved NoRobot, alternating between simplified and complex infection chains to hinder analysis while ensuring reliable delivery of its MaybeRobot PowerShell backdoor. Minor but frequent changes, such as rotating infrastructure, filenames, and export functions, demonstrate Coldriver’s adaptive tradecraft, forcing defenders to capture multiple components to fully reconstruct attacks. The GTIG report builds on a September Zscaler report, in which NoRobot is tracked as BaitSwitch and MaybeRobot as SimpleFix.
infosecurity-magazine.comOct 21, 2025extracted
Evilginx’s creator reckons with the dark side of red-team tools
Evilginx’s creator reckons with the dark side of red-team tools Kuba Gretzky wanted to make the internet safer. Instead, he helped make it more dangerous. In 2017, from his home in Poland, the coder released a hacking tool called Evilginx – a program designed to help cybersecurity teams understand and defend against phishing attacks. It was meant as a teaching device, a way for companies to see how easily credentials could be stolen and to shore up their defenses before someone else did it for real.But once Evilginx went public, the line between defense and offense blurred. Hackers began using it to break into networks, steal passwords and sell access. Before long, even nation-state actors were folding Gretzky’s code into their operations. At the center of the story is one of cybersecurity’s oldest paradoxes: The same code that helps protect systems can also be turned against them. It’s the open-source dilemma at internet scale, where “ethical” and “criminal” hacking are separated not by the software itself, but by whoever’s sitting at the keyboard. When asked if he ever feels like Dr. Frankenstein, Gretzky chuckles. The comparison fits. Frankenstein created a monster he couldn’t control; Gretzky created code that escaped its laboratory. “The bad guys started using it,” Gretzky says, “to do evil.” From gamer to red teamer Long before Evilginx, Gretzky spent long nights in front of his computer, playing massively multiplayer online games — the kind where strangers from around the world battle in virtual forests. The problem, he came to believe, was that when he logged off, his character stopped accumulating points; and he wondered whether he could find a way to have the game just keep playing without him. So he reverse-engineered its code and built a bot that could do the work automatically — slaying monsters, gathering loot, leveling up while he slept. And all these years later he says it was never about money — it was about curiosity. That impulse — to take things apart and see how they worked — eventually led him into cybersecurity. He became an offensive-security developer, building tools for “red teams,” the ethical hackers hired to break into systems before criminals do so companies can patch their network vulnerabilities. Kuba Gretzky speaks with the Click Here podcast team. Image: Recorded Future News It turns out Evilginx was his most ambitious creation. It could quietly intercept the text messages or app notifications that make up multi-factor authentication — that extra step protecting online accounts. The software acted as a kind of digital pickpocket, grabbing a user’s session token mid-air and handing it to whoever controlled the proxy. To Gretzky, it was a teaching tool. If he could build something that bypassed multi-factor authentication, he reasoned, so could someone else. By showing how easy it was, companies would be forced to strengthen their systems. So in 2017, he made Evilginx open-source. Anyone could download it. Within weeks, attackers did. Unintended consequences By late 2023, the tool was everywhere. A hacking collective called Scattered Spider had used it. The group is known for breaching MGM Resorts, making hotel keycards fail and freezing up slot machines. Guests couldn’t check in or cash out. The company reported losses of more than $100 million. Investigators linked Scattered Spider to Russian ransomware gangs. Another group — a Russian espionage gang known as Void Blizzard or Laundry Bear — used Evilginx to target NGOs and defense contractors supporting Ukraine. “That was a pretty … not fun … thing to read,” Gretzky admitted. For a Polish coder whose country still bears the scars of Russian occupation, the revelation cut deep. “I would never want to aid this country,” he says. “We have a bad history with what Russia is capable of.” To blunt the damage, Gretzky offered a scaled-back public version of Evilginx available on GitHub. He removed its most dangerous features and inserted digital “Easter eggs” — bits of code that allow researchers to spot when Evilginx is being used in the wild. The public release, he said, was like a family recipe with one ingredient missing. The full version, called Evilginx Pro, is sold privately to vetted security firms. Gretzky personally screens buyers to confirm they work for legitimate companies. Still, the free version remains online, and the decision to put it there continues to weigh on him. “I know that I’m basically, by proxy, aiding the bad guys,” he says. “But I also want to support people who can’t afford the private version, to help them strengthen their defenses.” Ironically, Evilginx has also driven improvements across the industry. Engineers at Google contacted Gretzky after his release, seeking advice on hardening their authentication systems. He believes the openness of tools like his ultimately makes the internet safer. “Otherwise,” he says, “people would just be sitting in the dark, waiting for attacks to happen without anyone knowing the technique is out there.” Seven years later, Evilginx still straddles the line between innovation and threat — a living example of what happens when transparency collides with opportunism. Gretzky remains convinced that shining a light on flaws is better than pretending they don’t exist, even if that light sometimes spills into the wrong places. Security, he says, isn’t one person’s responsibility. It’s a chain — from the coder to the company to the person who clicks the link. And every link in that chain has to hold. Dina Temple-Raston is the Host and Managing Editor of the Click Here podcast as well as a senior correspondent at Recorded Future News. She previously served on NPR’s Investigations team focusing on breaking news stories and national security, technology, and social justice and hosted and created the award-winning Audible Podcast “What Were You Thinking.”
therecord.mediaOct 20, 2025extracted
New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks
The Russian advanced persistent threat (APT) group known as COLDRIVER has been attributed to a fresh round of ClickFix-style attacks designed to deliver two new "lightweight" malware families tracked as BAITSWITCH and SIMPLEFIX. Zscaler ThreatLabz, which detected the new multi-stage ClickFix campaign earlier this month, described BAITSWITCH as a downloader that ultimately drops SIMPLEFIX, a PowerShell backdoor. COLDRIVER, also tracked as Callisto, Star Blizzard, and UNC4057, is the moniker assigned to a Russia-linked threat actor that's known to target a wide range of sectors since 2019. While early campaign waves were observed using spear-phishing lures to direct targets to credential harvesting pages, the group has been fleshing out its arsenal with custom tools like SPICA and LOSTKEYS, which underscores its technical sophistication. The adversary's use of ClickFix tactics was previously documented by the Google Threat Intelligence Group (GTIG) back in May 2025, using fake sites serving fake CAPTCHA verification prompts to trick the victim into executing a PowerShell command that's designed to deliver the LOSTKEYS Visual Basic Script. "The continued use of ClickFix suggests that it is an effective infection vector, even if it is neither novel nor technically advanced," Zscaler security researchers Sudeep Singh and Yin Hong Chang said in a report published this week. The latest attack chain follows the same modus operandi, tricking unsuspecting users into running a malicious DLL in the Windows Run dialog under the guise of completing a CAPTCHA check. The DLL, BAITSWITCH, reaches out to an attacker-controlled domain ("captchanom[.]top") to fetch the SIMPLEFIX backdoor, while a decoy document hosted on Google Drive is presented to the victims. It also makes several HTTP requests to the same server to send system information, receive commands to establish persistence, store encrypted payloads in the Windows Registry, download a PowerShell stager, clear the most recent command executed in the Run dialog, effectively erasing traces of the ClickFix attack that triggered the infection. The downloaded PowerShell stager subsequently reaches out to an external server ("southprovesolutions[.]com") to download SIMPLEFIX, which, in turn, establishes communication with a command-and-control (C2) server to run PowerShell scripts, commands, and binaries hosted on remote URLs. One of the PowerShell scripts executed via SIMPLEFIX exfiltrates information about a hard-coded list of file types found in a pre-configured list of directories. The list of directories and file extensions scanned shares overlaps with that of LOSTKEYS. "The COLDRIVER APT group is known for targeting members of NGOs, human right defenders, think tanks in Western regions, as well as individuals exiled from and residing in Russia," Zscaler said. "The focus of this campaign closely aligns with their victimology, which targets members of civil society connected to Russia." BO Team and Bearlyfy Target Russia The development comes as Kaspersky said it observed a new phishing campaign targeting Russian companies in early September undertaken by the BO Team group (aka Black Owl, Hoody Hyena, and Lifting Zmiy) using password-protected RAR archives to deliver a new version of BrockenDoor rewritten in C# and an updated version of ZeronetKit. A Golang backdoor, ZeronetKit, comes fitted with capabilities to support remote access to compromised hosts, upload/download files, execute commands using cmd.exe, and create a TCP/IPv4 tunnel. Select newer versions also incorporate support for downloading and running shellcode, as well as update the communication interval with C2 and modify the C2 server list. "ZeronetKit is unable to independently persist on an infected system, so attackers use BrockenDoor to copy the downloaded backdoor to startup," the Russian cybersecurity vendor said. It also follows the emergence of a new group called Bearlyfy that has used ransomware strains like LockBit 3.0 and Babuk in attacks targeting Russia, initially attacking smaller companies for smaller ransoms before graduating to bigger firms in the country starting April 2025, according to F6. As of August 2025, the group is estimated to have claimed at least 30 victims. In one incident targeting a consulting company, the threat actors have been observed weaponizing a vulnerable version of Bitrix for initial access, followed by using the Zerologon flaw to escalate privileges. In another case observed in July, the initial access is said to have been facilitated through an unnamed partner company. "In the most recent recorded attack, the attackers demanded €80,000 in cryptocurrency, while in the first attack, the ransom was several thousand dollars," F6 researchers said. "Due to the relatively low ransom amounts, on average, every fifth victim buys decryptors from the attackers." Bearlyfy is assessed to be active since January 2025, with a deeper analysis of its tools uncovering infrastructure overlaps with a likely pro-Ukrainian threat group called PhantomCore, which has a track record of targeting Russian and Belarusian companies since 2022. Despite these similarities, Bearlyfy is believed to be an autonomous entity. "PhantomCore implements complex, multi-stage attacks typical of APT campaigns," the company said. "Bearlyfy, on the other hand, uses a different model: attacks with minimal preparation and a targeted focus on achieving an immediate effect. Initial access is achieved through exploitation of external services and vulnerable applications. The primary toolkit is aimed at encryption, destruction, or modification of data."
thehackernews.comSep 26, 2025extracted
Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine
Cybersecurity researchers have discerned evidence of two Russian hacking groups Gamaredon and Turla collaborating together to target and co-comprise Ukrainian entities. Slovak cybersecurity company ESET said it observed the Gamaredon tools PteroGraphin and PteroOdd being used to execute Turla group's Kazuar backdoor on an endpoint in Ukraine in February 2025, indicating that Turla is very likely actively collaborating with Gamaredon to gain access to specific machines in Ukraine and deliver the Kazuar backdoor. "PteroGraphin was used to restart the Kazuar v3 backdoor, possibly after it crashed or was not launched automatically," ESET said in a report shared with The Hacker News. "Thus, PteroGraphin was probably used as a recovery method by Turla." In a separate instance in April and June 2025, ESET said it also detected the deployment of Kazuar v2 through two other Gamaredon malware families tracked as PteroOdd and PteroPaste. Both Gamaredon (aka Aqua Blizzard and Armageddon) and Turla (aka Secret Blizzard and Venomous Bear) are assessed to be affiliated with the Russian Federal Security Service (FSB), and are known for their attacks targeting Ukraine. "Gamaredon has been active since at least 2013. It is responsible for many attacks, mostly against Ukrainian governmental institutions," ESET said. "Turla, also known as Snake, is an infamous cyber espionage group that has been active since at least 2004, possibly extending back into the late 1990s. It mainly focuses on high-profile targets, such as governments and diplomatic entities, in Europe, Central Asia, and the Middle East. It is known for having breached major organizations such as the US Department of Defense in 2008 and the Swiss defense company RUAG in 2014." The cybersecurity company said Russia's full-scale invasion of Ukraine in 2022 likely fueled this convergence, with the attacks primarily focusing on the Ukrainian defense sector in recent months. One of Turla's staple implants is Kazuar, a frequently updated malware that has previously leveraged Amadey bots to deploy a backdoor called Tavdig, which then drops the .NET-based tool. Early artifacts associated with the malware have been spotted in the wild as far back as 2016, per Kaspersky. PteroGraphin, PteroOdd, and PteroPaste, on the other hand, are part of a growing arsenal of tools developed by Gamaredeon to deliver additional payloads. PteroGraphin is a PowerShell tool that uses Microsoft Excel add-ins and scheduled tasks as a persistence mechanism and uses the Telegraph API for command-and-control (C2). It was first discovered in August 2024. The exact initial access vector used by Gamaredon is not clear, but the group has a history of using spear-phishing and malicious LNK files on removable drives using tools like PteroLNK for propagation. In all, Turla-related indicators have been detected on seven machines in Ukraine over the past 18 months, out of which four were breached by Gamaredon in January 2025. The deployment of the latest version of Kazuar (Kazuar v3) is said to have taken place towards the end of February. "Kazuar v2 and v3 are fundamentally the same malware family and share the same codebase," ESET said. "Kazuar v3 comprises around 35% more C# lines than Kazuar v2 and introduces additional network transport methods: over web sockets and Exchange Web Services." The attack chain involved Gamaredon deploying PteroGraphin, which was used to download a PowerShell downloader dubbed PteroOdd that, in turn, retrieved a payload from Telegraph to execute Kazuar. The payload is also designed to gather and exfiltrate the victim's computer name and system drive's volume serial number to a Cloudflare Workers sub-domain, before launching Kazuar. That said, it's important to note here that there are signs suggesting Gamaredon downloaded Kazuar, as the backdoor is said to have been present on the system since February 11, 2025. In a sign that this was not an isolated phenomenon, ESET revealed that it identified another PteroOdd sample on a different machine in Ukraine in March 2025, on which Kazuar was also present. The malware is capable of harvesting a wide range of system information, along with a list of installed .NET versions, and transmitting them to an external domain ("eset.ydns[.]eu"). The fact that Gamaredon's toolset lacks any .NET malware and Turla's Kazuar is based in .NET suggests this data gathering step is likely meant for Turla, the company assessed with medium confidence. The second set of attacks was detected in mid-April 2025, when PteroOdd was used to drop another PowerShell downloader codenamed PteroEffigy, which ultimately contacted the "eset.ydns[.]eu" domain to deliver Kazuar v2 ("scrss.ps1"), which was documented by Palo Alto Networks in late 2023. ESET said it also detected a third attack chain on June 5 and 6, 2025, it observed a PowerShell downloader referred to as PteroPaste being employed to drop and install Kazuar v2 ("ekrn.ps1") from the domain "91.231.182[.]187" on two machines located in Ukraine. The use of the name "ekrn" is possibly an attempt by threat actors to masquerade as "ekrn.exe," a legitimate binary associated with ESET endpoint security products. "We now believe with high confidence that both groups – separately associated with the FSB – are cooperating and that Gamaredon is providing initial access to Turla," ESET researchers Matthieu Faou and Zoltán Rusnák said.
thehackernews.comSep 19, 2025extracted
New Zealand sanctions Russian military hackers over cyberattacks on Ukraine
New Zealand sanctions Russian military hackers over cyberattacks on Ukraine New Zealand has imposed sanctions on Russian military intelligence hackers accused of cyberattacks on Ukraine, including members of a notorious hacking unit previously tied to destructive malware campaigns. The sanctions announced Friday target Unit 29155 of Russia’s GRU intelligence agency. Western security agencies say the unit — also tracked by researchers as Cadet Blizzard and Ember Bear — has been involved in espionage, sabotage, and assassination plots across Europe. It was behind the 2022 WhisperGate malware attack on Ukrainian government networks ahead of Moscow’s full-scale invasion. “Russian state actors have been illegally using malware against Ukrainian government networks,” New Zealand Foreign Minister Winston Peters said in a statement on Friday, without giving further details. Ukrainian President Volodymyr Zelensky welcomed the move, describing New Zealand’s latest sanctions on Russia as “a strong signal of support for Ukraine.” The sanctions impose an asset freeze, a travel ban and prohibit New Zealand citizens and companies from making funds available to the designated entities. According to a joint advisory by several U.S. federal agencies, Unit 29155 has since 2022 focused on disrupting aid to Ukraine through destructive cyber campaigns, data theft and reconnaissance operations in Europe, North America, Latin America and Central Asia. In 2024, the U.S. Justice Department indicted members of the unit and offered rewards of up to $10 million for information leading to their prosecution. The hackers have also been targeted by sanctions elsewhere. In January, the European Union sanctioned three alleged members of Unit 29155 over cyberattacks on Estonian ministries in 2020 that stole thousands of confidential government and business documents. In July, Britain sanctioned three GRU units, including Unit 29155, accusing them of reconnaissance operations that facilitated strikes leading to civilian deaths in Ukraine. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaSep 15, 2025extracted
Amazon Disrupts Russian Hacking Campaign Targeting Microsoft Users
Amazon has disrupted a Russian watering hole campaign targeting Microsoft users via compromised websites opportunistically redirecting users to malicious infrastructure. Attributed to the state-sponsored cyberespionage group known as Midnight Blizzard (also tracked as APT29, Cozy Bear, the Dukes, and Yttrium) and believed to be sponsored by the Russian Foreign Intelligence Service (SVR), the attacks were focused on credential harvesting and intelligence collection. The APT compromised legitimate websites and injected JavaScript code that redirected visitors to domains controlled by the attackers, such as findcloudflare[.]com, which mimicked a Cloudflare verification page. Once redirected to the malicious domains, the victims were tricked into logging into their Microsoft accounts and authorizing devices under the attacker’s control, through the Microsoft device code authentication flow. According to Amazon CISO CJ Moses, only approximately 10% of the compromised website’s visitors were redirected to the threat actor-controlled domains. “This opportunistic approach illustrates APT29’s continued evolution in scaling their operations to cast a wider net in their intelligence collection efforts,” Moses notes. As part of the attacks, Midnight Blizzard relied on randomization to only redirect a small percentage of visitors, hid malicious code using base64 encoding, and set up cookies to prevent the repeated redirection of the same victims. When blocked, the attackers quickly set up new infrastructure, including by moving to a new cloud provider and by registering the domain cloudflare[.]redirectpartners[.]com, AWS says. “There was no compromise of AWS systems, nor was there a direct impact observed on AWS services or infrastructure,” Moses points out. Last year, Midnight Blizzard impersonated AWS and Microsoft employees to deliver RDP configuration files to unsuspecting users. In June 2025, Google warned of APT’s attacks targeting the “app-specific password” feature to trick Gmail users into providing MFA-free access to their accounts. Related: Russian State Hackers Target Organizations With Device Code Phishing Related: HPE Says Personal Information Stolen in 2023 Russian Hack Related: Russian APT Exploiting 7-Year-Old Cisco Vulnerability: FBI
securityweek.comSep 2, 2025extracted
Loading 10 more…